VYPR
Vendor

Apolloconfig

Products
3
CVEs
10
Across products
11
Status
Private

Products

3

Recent CVEs

10
  • CVE-2024-42662HigAug 20, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in apollocongif apollo v.2.2.0 allows a remote attacker to obtain sensitive information via a crafted request.

  • CVE-2026-59955HigJul 15, 2026
    risk 0.42cvss 7.5epss 0.00

    Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.2, Apollo ConfigService may allow unauthorized access to raw configuration data when AccessKey or management key authentication is enabled because…

  • CVE-2026-59954HigJul 15, 2026
    risk 0.42cvss 7.5epss 0.00

    Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.2, Apollo ConfigService may allow unauthorized access to configuration data when AccessKey or management key authentication is enabled because…

  • CVE-2023-25570HigFeb 20, 2023
    risk 0.42cvss 7.5epss 0.01

    Apollo is a configuration management system. Prior to version 2.1.0, there are potential security issues if users expose apollo-configservice to the internet, which is not recommended. This is because there is no authentication feature enabled for the built-in eureka service.…

  • CVE-2025-32781MedJul 15, 2026
    risk 0.35cvss 6.5epss 0.00

    Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does not verify application and namespace permissions when an authenticated user requests a release by ID through GET…

  • CVE-2023-25569MedFeb 20, 2023
    risk 0.30cvss 5.7epss 0.00

    Apollo is a configuration management system. Prior to version 2.1.0, a low-privileged user can create a special web page. If an authenticated portal admin visits this page, the page can silently send a request to assign new roles for that user without any confirmation from the…

  • CVE-2015-10043MedJan 14, 2023
    risk 0.29cvss 5.5epss 0.01

    A vulnerability, which was classified as critical, was found in abreen Apollo. This affects an unknown part. The manipulation of the argument file leads to path traversal. The patch is named 6206406630780bbd074aff34f4683fb764faba71. It is recommended to apply a patch to fix this…

  • CVE-2022-4962MedJan 12, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Apollo 2.0.0/2.0.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /users of the component Configuration Center. The manipulation leads to improper authorization. The attack may be launched remotely.…

  • CVE-2024-43397MedAug 20, 2024
    risk 0.21cvss 4.3epss 0.00

    Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks. This exploit enables them to modify a namespace without the necessary permissions. The issue…

  • CVE-2009-1351Apr 21, 2009
    risk 0.03cvss epss 0.06

    Heap-based buffer overflow in Apollo 37zz allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long URI in a playlist (.m3u) file.