Security Advisory

CVE-2025-32781

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-15 16:31:56
Last updated 2026-07-15 17:29:51
Assigner GitHub_M
CVSS score 6.5
State PUBLISHED

Description

Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does not verify application and namespace permissions when an authenticated user requests a release by ID through GET /envs/{env}/releases/{releaseId} while configView.memberOnly.envs is enabled, allowing a low-privileged Portal user who obtains or guesses a valid releaseId to read configuration data from other applications and namespaces without calling UserPermissionValidator.shouldHideConfigToCurrentUser(...). This issue is fixed in version 2.5.0.