Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Apollo ConfigService access key authentication bypass via raw config file appId parsing
Vulnerability Description
Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.2, Apollo ConfigService may allow unauthorized access to raw configuration data when AccessKey or management key authentication is enabled because requests under /configfiles/raw/{appId}/{clusterName}/{namespace} are parsed for authentication as appId raw instead of the actual path appId, causing ConfigService to look up AccessKey secrets for raw before verifying the request signature and potentially continue without signature verification for the target appId. This issue is fixed in version 2.5.2.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
输入验证不恰当
Vulnerability Title
Apollo 输入验证错误漏洞
Vulnerability Description
Apollo Apollo是Apollo公司的一个可靠的配置管理系统。 apolloconfig apollo 2.5.2之前版本存在安全漏洞,该漏洞源于当AccessKey或管理密钥身份验证启用时,对/configfiles/raw/{appId}/{clusterName}/{namespace}下的请求进行身份验证解析时,将appId解析为raw而非实际路径中的appId,导致ConfigService在验证请求签名前先查找raw的AccessKey密钥,可能绕过目标appId的签名验证,从而导致未
CVSS Information
N/A
Vulnerability Type
N/A