« Volver al listado

CVE-2025-32781

Estado: AplazadaMedia (6.5)—

Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does not verify application and namespace permissions when an authenticated user requests a release by ID through GET /envs/{env}/releases/{releaseId} while configView.memberOnly.envs is enabled, allowing a low-privileged Portal user who obtains or guesses a valid releaseId to read configuration data from other applications and namespaces without calling UserPermissionValidator.shouldHideConfigToCurrentUser(...). This issue is fixed in version 2.5.0.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-32781",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-32781",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-07-15T17:29:45.653375Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "apolloconfig",
          "product": "apollo",
          "versions": [
            {
              "status": "affected",
              "version": "< 2.5.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-07-15T17:16:45.317",
  "references": [
    {
      "url": "https://github.com/apolloconfig/apollo/commit/362735ded4f13b62f6ab9df135d7096066e8e291",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/apolloconfig/apollo/pull/5378",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/apolloconfig/apollo/releases/tag/v2.5.0",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/apolloconfig/apollo/security/advisories/GHSA-jxpj-9j24-w337",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-639"
        },
        {
          "lang": "en",
          "value": "CWE-862"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does not verify application and namespace permissions when an authenticated user requests a release by ID through GET /envs/{env}/releases/{releaseId} while configView.memberOnly.envs is enabled, allowing a low-privileged Portal user who obtains or guesses a valid releaseId to read configuration data from other applications and namespaces without calling UserPermissionValidator.shouldHideConfigToCurrentUser(...). This issue is fixed in version 2.5.0."
    },
    {
      "lang": "es",
      "value": "Apollo es un sistema fiable de gestión de configuración adecuado para escenarios de gestión de configuración de microservicios. Antes de la versión 2.5.0, Apollo Portal no verifica los permisos de aplicación y de espacio de nombres cuando un usuario autenticado solicita una versión por ID a través de GET /envs/{env}/releases/{releaseId} mientras configView.memberOnly.envs está habilitado, permitiendo a un usuario de Portal con bajos privilegios que obtiene o adivina un releaseId válido leer datos de configuración de otras aplicaciones y espacios de nombres sin llamar a UserPermissionValidator.shouldHideConfigToCurrentUser(...). Este problema está solucionado en la versión 2.5.0."
    }
  ],
  "lastModified": "2026-09-29T15:10:00.193",
  "sourceIdentifier": "security-advisories@github.com"
}