Vulnerability Description
Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does not verify application and namespace permissions when an authenticated user requests a release by ID through GET /envs/{env}/releases/{releaseId} while configView.memberOnly.envs is enabled, allowing a low-privileged Portal user who obtains or guesses a valid releaseId to read configuration data from other applications and namespaces without calling UserPermissionValidator.shouldHideConfigToCurrentUser(...). This issue is fixed in version 2.5.0.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/apolloconfig/apollo/commit/362735ded4f13b62f6ab9df135d7096066
- https://github.com/apolloconfig/apollo/pull/5378
- https://github.com/apolloconfig/apollo/releases/tag/v2.5.0
- https://github.com/apolloconfig/apollo/security/advisories/GHSA-jxpj-9j24-w337
FAQ
What is CVE-2025-32781?
CVE-2025-32781 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does not verify application and namespace permissions w...
How severe is CVE-2025-32781?
CVE-2025-32781 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-32781?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.