2.0.1
6 years ago
2 years ago
Known vulnerabilities in the com.ctrip.framework.apollo:apollo package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) allowing low-privileged users to create a page that can silently sends a request to assign new roles for an authenticated portal admin without any additional confirmation. How to fix Cross-site Request Forgery (CSRF)? A fix was pushed into the | [0,) |
Affected versions of this package are vulnerable to Improper Authentication in How to fix Improper Authentication? A fix was pushed into the | [0,) |