CVE-2025-32781
- EPSS 0.3%
- Veröffentlicht 15.07.2026 16:31:56
- Zuletzt bearbeitet 15.07.2026 18:16:44
Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does not verify application and namespace permissions when an authenticated user requests a release by ID...
CVE-2026-59954
- EPSS 0.41%
- Veröffentlicht 15.07.2026 16:27:48
- Zuletzt bearbeitet 15.07.2026 18:16:49
Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.2, Apollo ConfigService may allow unauthorized access to configuration data when AccessKey or management key authenticatio...
CVE-2026-59955
- EPSS 0.41%
- Veröffentlicht 15.07.2026 16:26:05
- Zuletzt bearbeitet 15.07.2026 19:18:34
Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.2, Apollo ConfigService may allow unauthorized access to raw configuration data when AccessKey or management key authentic...
CVE-2024-42662
- EPSS 0.53%
- Veröffentlicht 20.08.2024 15:15:23
- Zuletzt bearbeitet 14.03.2025 15:15:42
An issue in apollocongif apollo v.2.2.0 allows a remote attacker to obtain sensitive information via a crafted request.
CVE-2024-43397
- EPSS 0.35%
- Veröffentlicht 20.08.2024 15:15:23
- Zuletzt bearbeitet 26.08.2024 18:28:42
Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks. This exploit enables them to modify a namespace without the nec...
CVE-2022-4962
- EPSS 0.46%
- Veröffentlicht 12.01.2024 22:15:44
- Zuletzt bearbeitet 21.11.2024 07:36:20
A vulnerability was found in Apollo 2.0.0/2.0.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /users of the component Configuration Center. The manipulation leads to improper authorization. The attack...
CVE-2023-25569
- EPSS 0.35%
- Veröffentlicht 20.02.2023 16:15:10
- Zuletzt bearbeitet 21.11.2024 07:49:44
Apollo is a configuration management system. Prior to version 2.1.0, a low-privileged user can create a special web page. If an authenticated portal admin visits this page, the page can silently send a request to assign new roles for that user withou...
CVE-2023-25570
- EPSS 0.82%
- Veröffentlicht 20.02.2023 16:15:10
- Zuletzt bearbeitet 21.11.2024 07:49:45
Apollo is a configuration management system. Prior to version 2.1.0, there are potential security issues if users expose apollo-configservice to the internet, which is not recommended. This is because there is no authentication feature enabled for th...