漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Apollo ConfigService access key authentication bypass via raw config file appId parsing
Vulnerability Description
Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.2, Apollo ConfigService may allow unauthorized access to raw configuration data when AccessKey or management key authentication is enabled because requests under /configfiles/raw/{appId}/{clusterName}/{namespace} are parsed for authentication as appId raw instead of the actual path appId, causing ConfigService to look up AccessKey secrets for raw before verifying the request signature and potentially continue without signature verification for the target appId. This issue is fixed in version 2.5.2.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
输入验证不恰当
Vulnerability Title
Apollo 输入验证错误漏洞
Vulnerability Description
Apollo Apollo是Apollo公司的一个可靠的配置管理系统。 apolloconfig apollo 2.5.2之前版本存在安全漏洞,该漏洞源于当AccessKey或管理密钥身份验证启用时,对/configfiles/raw/{appId}/{clusterName}/{namespace}下的请求进行身份验证解析时,将appId解析为raw而非实际路径中的appId,导致ConfigService在验证请求签名前先查找raw的AccessKey密钥,可能绕过目标appId的签名验证,从而导致未
CVSS Information
N/A
Vulnerability Type
N/A