Executive brief
Apollo is a configuration management system used to manage application settings across environments. A security issue exists where the built-in service discovery component (Eureka) lacks authentication by default. If this service is exposed to the internet, unauthorized users could impersonate core Apollo services, potentially leading to the distribution of malicious configuration data to connected applications.
Technical details
Apollo versions prior to 2.1.0 contain a missing authentication vulnerability (CWE-306) in the built-in Eureka service component. The root cause is that the `apollo-configservice` does not enforce credentials for Eureka interactions by default. A network-based attacker can access the Eureka registry without authentication to register rogue instances, effectively mocking the `apollo-configservice` and `apollo-adminservice`. This can be exploited to intercept or provide fraudulent configuration data to clients. The issue is mitigated by upgrading to version 2.1.0, which introduces login authentication for Eureka, or by ensuring the service is not reachable from the public internet.
Affected products
- apolloconfig Apollo < 2.1.0
Timeline
- 2022-11-26: other: Initial pull request created to add authentication
- 2023-02-18: advisory: GitHub Advisory published
- 2023-02-20: disclosed: NVD publication date
- 2023-02-22: patched: Official release of version 2.1.0
References
- https://github.com/apolloconfig/apollo/security/advisories/GHSA-368x-wmmg-hq5c
- https://github.com/apolloconfig/apollo/pull/4663
- https://github.com/apolloconfig/apollo/commit/7df79bf8df6960433ed4ff782a54e3dfc74632bd
- https://github.com/apolloconfig/apollo/releases/tag/v2.1.0
- https://api.github.com/repos/apolloconfig/apollo/security-advisories/GHSA-368x-wmmg-hq5c