Back

CVE-2019-10686

CRITICAL

An SSRF vulnerability was found in an API from Ctrip Apollo through 1.4.0-SNAPSHOT. An attacker may use it to do an intranet port scan or raise a GET request via /system-info/health because the %23 substring is mishandled.

Published: Apr 1, 2019 Modified: Jun 17, 2026
CWE-918

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: CHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
ctrip apollo *

GitHub Security Advisory GHSA-fvx3-g627-phm2

Server-Side Request Forgery (SSRF) in com.ctrip.framework.apollo:apollo

maven com.ctrip.framework.apollo:apollo <= 1.3.0

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 1.56%

Top 27% most likely to be exploited

Threat Score 40.5 / 100

Data Sources

NVD EPSS GitHub