Total vulnerabilities in the database
An SSRF vulnerability was found in an API from Ctrip Apollo through 1.4.0-SNAPSHOT. An attacker may use it to do an intranet port scan or raise a GET request via /system-info/health because the %23 substring is mishandled.
Software | From | Fixed in |
---|---|---|
ctrip / apollo | - | 1.3.0.x |
![]() |
- | 1.3.0.x |