CVE-2024-43397 MEDIUM

CVE-2024-43397: Potential unauthorized access issue in apollo-portal

Vendor Apolloconfig
Product apollo
Weakness CWE-284
Published August 20, 2024
Last update August 20, 2024

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks. This exploit enables them to modify a namespace without the necessary permissions. The issue was addressed with an input parameter check which was released in version 2.3.0.

Key dates

02Disclosure timeline

August 20, 2024 CVE published
August 20, 2024 Record updated