ctrip records
2 published records for vendor ctrip.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Attack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-10686No exploit | An SSRF vulnerability was found in an API from Ctrip Apollo through 1.4.0-SNAPSHOT.ctrip · apollo · CWE-918 | Critical10.0 | — | 1.6% | Apr 1, 2019 |
28Monitor | CVE-2020-15170No exploit | Missing access control in apollo-adminservicectrip · apollo · CWE-20 | High7.0 | — | 1.3% | Sep 10, 2020 |
- CVE-2019-1068640Plan
An SSRF vulnerability was found in an API from Ctrip Apollo through 1.4.0-SNAPSHOT.
CriticalCVSS 10.0No exploitEPSS 2%ctrip · apolloApr 1, 2019
- CVE-2020-1517028Monitor
Missing access control in apollo-adminservice
HighCVSS 7.0No exploitEPSS 1%ctrip · apolloSep 10, 2020