CVE-2024-43397: Apolloconfig Apollo
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks. This exploit enables them to modify a namespace without the necessary permissions. The issue was addressed with an input parameter check which was released in version 2.3.0.
Affected products
- Apolloconfig Apollo: before 2.3.0 (fixed in 2.3.0)
Published 2024-08-20. Last modified 2026-06-17.