
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-15170 affects apollo-adminservice versions before 1.7.1. The vulnerability exists because apollo-adminservice does not implement access controls. The issue was discovered and disclosed on September 10, 2020, and was patched in version 1.7.1 (GitHub Advisory).
The vulnerability stems from a lack of built-in access control mechanisms in apollo-adminservice. The service was designed to work in intranet environments but without proper authentication controls. This could allow unauthorized access to the service's APIs. The CVSS v3.1 base score is 7.0 (HIGH) with vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L (NVD).
If apollo-adminservice is exposed to the internet, malicious actors could directly access the service's APIs to view and modify application configurations without authorization. This could lead to unauthorized access to sensitive configuration data and potential modification of application settings (GitHub Advisory).
The vulnerability requires network access to the apollo-adminservice endpoint. While the attack complexity is rated as high, no authentication is required to exploit the vulnerability if the service is exposed to the internet (NVD).
The vulnerability was patched in apollo-adminservice version 1.7.1 by adding access control support. For users unable to upgrade, the recommended workaround is to ensure apollo-adminservice is not exposed to the internet, as it is designed for intranet use only (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."