CVE-2025-32781

Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does not verify application and namespace permissions when an authenticated user requests a release by ID through GET /envs/{env}/releases/{releaseId} while configView.memberOnly.envs is enabled, allowing a low-privileged Portal user who obtains or guesses a valid releaseId to read configuration data from other applications and namespaces without calling UserPermissionValidator.shouldHideConfigToCurrentUser(...). This issue is fixed in version 2.5.0.
Configurations

No configuration.

History

15 Jul 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-15 17:16

Updated : 2026-07-15 18:16


NVD link : CVE-2025-32781

Mitre link : CVE-2025-32781

CVE.ORG link : CVE-2025-32781


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key

CWE-862

Missing Authorization