Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Lakeswang

#47602of 53,624
5.3Total CVSS
Vulnerabilities · 1
PT-2024-30557
5.3
2024-08-20
Apollo · Apollo · CVE-2024-43397
**Name of the Vulnerable Software and Affected Versions** Apollo versions prior to 2.3.0 **Description** A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks, enabling them to modify a namespace without the necessary permissions. **Recommendations** For versions prior to 2.3.0, update to version 2.3.0 to address the issue. As a temporary workaround, follow the recommended practices to prevent Apollo from being exposed to the internet.