CVE-2025-21092

Name
CVE-2025-21092
Description
GMOD Apollo does not have sufficient logical or access checks when updating a user's information. This could result in an attacker being able to escalate privileges for themselves or others.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
ics-cert@hq.dhs.gov https://www.cisa.gov/news-events/ics-advisories/icsa-25-063-07

Match rules

CPE URI Source package Min version Max version
apollo >= 0 < 2.8.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
apollo edge-community 0.3.1-r6 David Sugar <tychosoft@gmail.com> possibly vulnerable
apollo edge-community 0.3.1-r5 David Sugar <tychosoft@gmail.com> possibly vulnerable
apollo edge-community 0.3.1-r4 David Sugar <tychosoft@gmail.com> possibly vulnerable
apollo edge-community 0.3.1-r3 David Sugar <tychosoft@gmail.com> possibly vulnerable
apollo edge-community 0.3.1-r2 David Sugar <tychosoft@gmail.com> possibly vulnerable
apollo edge-community 0.3.1-r1 David Sugar <tychosoft@gmail.com> possibly vulnerable
apollo edge-community 0.3.1-r0 David Sugar <tychosoft@gmail.com> possibly vulnerable
apollo edge-community 0.3.0-r3 David Sugar <tychosoft@gmail.com> possibly vulnerable
apollo edge-community 0.3.0-r2 David Sugar <tychosoft@gmail.com> possibly vulnerable
apollo edge-community 0.3.0-r1 David Sugar <tychosoft@gmail.com> possibly vulnerable
apollo edge-community 0.3.0-r0 David Sugar <tychosoft@gmail.com> possibly vulnerable
apollo edge-community 0.2.3-r2 David Sugar <tychosoft@gmail.com> possibly vulnerable
apollo edge-community 0.2.3-r1 David Sugar <tychosoft@gmail.com> possibly vulnerable
apollo edge-community 0.2.3-r0 David Sugar <tychosoft@gmail.com> possibly vulnerable
apollo 3.23-community 0.3.1-r6 David Sugar <tychosoft@gmail.com> possibly vulnerable
apollo 3.23-community 0.3.1-r5 David Sugar <tychosoft@gmail.com> possibly vulnerable
apollo 3.22-community 0.3.0-r7 David Sugar <tychosoft@gmail.com> possibly vulnerable
apollo 3.22-community 0.3.0-r6 David Sugar <tychosoft@gmail.com> possibly vulnerable
apollo 3.22-community 0.3.0-r5 David Sugar <tychosoft@gmail.com> possibly vulnerable
apollo 3.22-community 0.3.0-r4 David Sugar <tychosoft@gmail.com> possibly vulnerable