CVE-2021-32691 is a critical authentication bypass vulnerability affecting Apollos Apps versions prior to 2.20.0, specifically impacting the data-connector-rock component. An unauthenticated attacker can gain full access to any user's account by knowing basic profile information like name, birthday, and gender. This allows access to all in-app functionality and authenticated links to Rock-based webpages. With a CVSS score of 9.8 (CRITICAL), this vulnerability is easily exploitable over the network with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion with 10 mentions, indicating awareness. A patch is available in version 2.20.0, and a server-side workaround is also provided.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.20.0CPE matchmatch criteria | cpe:2.3:a:apollosapp:data-connector-rock:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.