CVE-2020-15170
Java vulnerability analysis and mitigation

Overview

CVE-2020-15170 affects apollo-adminservice versions before 1.7.1. The vulnerability exists because apollo-adminservice does not implement access controls. The issue was discovered and disclosed on September 10, 2020, and was patched in version 1.7.1 (GitHub Advisory).

Technical details

The vulnerability stems from a lack of built-in access control mechanisms in apollo-adminservice. The service was designed to work in intranet environments but without proper authentication controls. This could allow unauthorized access to the service's APIs. The CVSS v3.1 base score is 7.0 (HIGH) with vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L (NVD).

Impact

If apollo-adminservice is exposed to the internet, malicious actors could directly access the service's APIs to view and modify application configurations without authorization. This could lead to unauthorized access to sensitive configuration data and potential modification of application settings (GitHub Advisory).

Exploitability

The vulnerability requires network access to the apollo-adminservice endpoint. While the attack complexity is rated as high, no authentication is required to exploit the vulnerability if the service is exposed to the internet (NVD).

Mitigation and workarounds

The vulnerability was patched in apollo-adminservice version 1.7.1 by adding access control support. For users unable to upgrade, the recommended workaround is to ensure apollo-adminservice is not exposed to the internet, as it is designed for intranet use only (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-73644CRITICAL9.6
  • Java logoJava
  • org.openidentityplatform.opendj:opendj-server-legacy
NoYesAug 13, 2026
CVE-2026-73507HIGH7.5
  • Java logoJava
  • seata
NoYesAug 13, 2026
CVE-2026-49989HIGH7.1
  • Java logoJava
  • io.crate:crate
NoYesAug 14, 2026
CVE-2026-53660HIGH7
  • Java logoJava
  • org.openidentityplatform.openam:openam-core
NoYesAug 14, 2026
CVE-2026-73508MEDIUM5.3
  • Java logoJava
  • celeborn-0.6
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management