Medium severity4.3NVD Advisory· Published Jan 12, 2024· Updated Jun 17, 2026
CVE-2022-4962
CVE-2022-4962
Description
A vulnerability was found in Apollo 2.0.0/2.0.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /users of the component Configuration Center. The manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. VDB-250430 is the identifier assigned to this vulnerability. NOTE: The maintainer explains that user data information like user id, name, and email are not sensitive.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:apolloconfig:apollo:2.0.0:-:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:apolloconfig:apollo:2.0.0:-:*:*:*:*:*:*
- cpe:2.3:a:apolloconfig:apollo:2.0.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:apolloconfig:apollo:2.0.1:*:*:*:*:*:*:*
- Apollo/Configuration Centerdescription
Patches
Vulnerability mechanics
References
3- github.com/apolloconfig/apollo/issues/4684nvdExploitIssue TrackingThird Party Advisory
- vuldb.comnvdPermissions RequiredThird Party Advisory
- vuldb.comnvdPermissions RequiredThird Party Advisory
News mentions
0No linked articles in our index yet.