Apollo · Apollo · CVE-2024-43397
**Name of the Vulnerable Software and Affected Versions**
Apollo versions prior to 2.3.0
**Description**
A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks, enabling them to modify a namespace without the necessary permissions.
**Recommendations**
For versions prior to 2.3.0, update to version 2.3.0 to address the issue.
As a temporary workaround, follow the recommended practices to prevent Apollo from being exposed to the internet.