Executive brief
Apollo is a configuration management system used to manage settings for microservices. A security flaw in the ConfigService component allows unauthorized users to bypass authentication and access raw configuration data. This could lead to the exposure of sensitive application secrets, database credentials, or internal system settings, potentially compromising the entire microservice environment.
Technical details
An authentication bypass exists in Apollo ConfigService's handling of requests to the '/configfiles/raw/{appId}/{clusterName}/{namespace}' endpoint. The vulnerability stems from the service incorrectly parsing the string 'raw' as the appId for authentication purposes instead of extracting the actual appId from the URI path. Because the system looks up AccessKey secrets for the literal appId 'raw', it may find no associated secrets and proceed without requiring a valid signature, even if the target appId in the path requires authentication. An unauthenticated remote attacker can exploit this to retrieve raw configuration files. The issue is addressed in version 2.5.2 by ensuring the correct appId is validated during the authentication process.
Affected products
- ApolloConfig Apollo ConfigService < 2.5.2
Timeline
- 2026-07-12: patched: Version 2.5.2 released
- 2026-07-15: disclosed: NVD publication date