All 10 CVE vulnerabilities found in Apollo, with AI-generated Chinese analysis, references, and POCs.
Vendor: abreen
| CVE ID | Title | CVSS | Severity | Paused |
|---|---|---|---|---|
| CVE-2025-20002 | GMOD Apollo Generation of Error Message Containing Sensitive Information CWE-209 | 5.3 | Medium | 2025-03-05 |
| CVE-2025-24924 | GMOD Apollo Missing Authentication for Critical Function CWE-306 | 9.8 | Critical | 2025-03-05 |
| CVE-2025-23410 | GMOD Apollo Relative Path Traversal CWE-23 | 9.8 | Critical | 2025-03-04 |
| CVE-2025-21092 | GMOD Apollo Incorrect Privilege Assignment CWE-266 | 6.5 | Medium | 2025-03-04 |
| CVE-2024-43397 | Potential unauthorized access issue in apollo-portal CWE-284 | 4.3 | Medium | 2024-08-20 |
| CVE-2022-4962 | Apollo Configuration Center users improper authorization CWE-285 | 4.3 | Medium | 2024-01-12 |
| CVE-2023-25570 | Apollo has potential access control security issue in eureka CWE-306 | 7.5 | High | 2023-02-20 |
| CVE-2023-25569 | apollo-portal has potential CSRF issue CWE-352 | 5.7 | Medium | 2023-02-20 |
| CVE-2015-10043 | abreen Apollo path traversal CWE-22 | 5.5 | Medium | 2023-01-14 |
| CVE-2020-15170 | Missing access control in apollo-adminservice CWE-20 | 7.0 | High | 2020-09-10 |
All 10 known CVE vulnerabilities affecting Apollo with full Chinese analysis, references, and POCs where available.