VYPR

Maven package

com.ctrip.framework.apollo/apollo-core

pkg:maven/com.ctrip.framework.apollo/apollo-core

Vulnerabilities (1)

  • CVE-2020-15170Sep 10, 2020
    affected < 1.7.1fixed 1.7.1

    apollo-adminservice before version 1.7.1 does not implement access controls. If users expose apollo-adminservice to internet(which is not recommended), there are potential security issues since apollo-adminservice is designed to work in intranet and it doesn't have access control