CVE-2025-32781
Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does not verify application and namespace permissions when an authenticated user requests a release by ID through GET /envs/{env}/releases/{releaseId} while configView.memberOnly.envs is enabled, allowing a low-privileged Portal user who obtains or guesses a valid releaseId to read configuration data from other applications and namespaces without calling UserPermissionValidator.shouldHideConfigToCurrentUser(...). This issue is fixed in version 2.5.0.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.41%
- Percentil entre todas las CVEs puntuadas: 34
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-639, CWE-862
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-32781",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-32781",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-07-15T17:29:45.653375Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "apolloconfig",
"product": "apollo",
"versions": [
{
"status": "affected",
"version": "< 2.5.0"
}
]
}
]
}
],
"published": "2026-07-15T17:16:45.317",
"references": [
{
"url": "https://github.com/apolloconfig/apollo/commit/362735ded4f13b62f6ab9df135d7096066e8e291",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/apolloconfig/apollo/pull/5378",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/apolloconfig/apollo/releases/tag/v2.5.0",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/apolloconfig/apollo/security/advisories/GHSA-jxpj-9j24-w337",
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-639"
},
{
"lang": "en",
"value": "CWE-862"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does not verify application and namespace permissions when an authenticated user requests a release by ID through GET /envs/{env}/releases/{releaseId} while configView.memberOnly.envs is enabled, allowing a low-privileged Portal user who obtains or guesses a valid releaseId to read configuration data from other applications and namespaces without calling UserPermissionValidator.shouldHideConfigToCurrentUser(...). This issue is fixed in version 2.5.0."
},
{
"lang": "es",
"value": "Apollo es un sistema fiable de gestión de configuración adecuado para escenarios de gestión de configuración de microservicios. Antes de la versión 2.5.0, Apollo Portal no verifica los permisos de aplicación y de espacio de nombres cuando un usuario autenticado solicita una versión por ID a través de GET /envs/{env}/releases/{releaseId} mientras configView.memberOnly.envs está habilitado, permitiendo a un usuario de Portal con bajos privilegios que obtiene o adivina un releaseId válido leer datos de configuración de otras aplicaciones y espacios de nombres sin llamar a UserPermissionValidator.shouldHideConfigToCurrentUser(...). Este problema está solucionado en la versión 2.5.0."
}
],
"lastModified": "2026-09-29T15:10:00.193",
"sourceIdentifier": "security-advisories@github.com"
}