CVE-2025-32781
Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Po
CVSS
6.5
Medium
EPSS
0.4%
p34
KEV
—
Exploit Today
10
0-100
Published: Jul 15, 2026 · Last modified: Jul 15, 2026 · CWE-639 · CWE-862
Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does not verify application and namespace permissions when an authenticated user requests a release by ID through GET /envs/{env}/releases/{releaseId} while configView.memberOnly.envs is enabled, allowing a low-privileged Portal user who obtains or guesses a valid releaseId to read configuration data from other applications and namespaces without calling UserPermissionValidator.shouldHideConfigToCurrentUser(...). This issue is fixed in version 2.5.0.
- github.comhttps://github.com/apolloconfig/apollo/commit/362735ded4f13b62f6ab9df135d7096066e8e291
- github.comhttps://github.com/apolloconfig/apollo/pull/5378
- github.comhttps://github.com/apolloconfig/apollo/releases/tag/v2.5.0
- github.comhttps://github.com/apolloconfig/apollo/security/advisories/GHSA-jxpj-9j24-w337