{"id":"GHSA-xpmx-h7xq-xffh","summary":"Potential access control security issue in apollo-adminservice","details":"### Impact\nIf users expose apollo-adminservice to internet(which is not recommended), there are potential security issues since apollo-adminservice is designed to work in intranet and it doesn't have built-in access control. Malicious hackers may access apollo-adminservice apis directly to access/edit the application's configurations.\n\n### Patches\nAccess control for admin service was added in #3233 and was released in [v1.7.1](https://github.com/ctripcorp/apollo/releases/tag/v1.7.1).\n\n### Workarounds\nTo fix the potential issue without upgrading, simply follow the advice that do not expose apollo-adminservice to internet.\n\n### Credits\n[Lexu](https://github.com/lllllx) reported the issue and provided the required information to reproduce it.\n\n### References\n[Apollo Security Guidence](https://github.com/ctripcorp/apollo/wiki/Apollo%E4%BD%BF%E7%94%A8%E6%8C%87%E5%8D%97#71-%E5%AE%89%E5%85%A8%E7%9B%B8%E5%85%B3)\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an [issue](https://github.com/ctripcorp/apollo/issues)\n* Email to one of the active [project maintainers](https://github.com/ctripcorp/apollo/graphs/contributors)","aliases":["CVE-2020-15170"],"modified":"2026-09-10T03:48:35.479433259Z","published":"2020-10-02T16:33:41Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-10-02T16:32:24Z","nvd_published_at":"2020-09-10T19:15:00Z","cwe_ids":["CWE-20"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/ctripcorp/apollo/security/advisories/GHSA-xpmx-h7xq-xffh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-15170"},{"type":"WEB","url":"https://github.com/ctripcorp/apollo/pull/3233/commits/ae9ba6cfd32ed80469f162e5e3583e2477862ddf"},{"type":"PACKAGE","url":"https://github.com/ctripcorp/apollo"}],"affected":[{"package":{"name":"com.ctrip.framework.apollo:apollo-core","ecosystem":"Maven","purl":"pkg:maven/com.ctrip.framework.apollo/apollo-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.7.1"}]}],"versions":["1.0.0","1.1.0","1.1.1","1.1.2","1.2.0","1.3.0","1.4.0","1.5.0","1.5.1","1.6.0","1.6.2","1.7.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/10/GHSA-xpmx-h7xq-xffh/GHSA-xpmx-h7xq-xffh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L"}]}