Impact
The vulnerability allows an attacker to retrieve the entire configuration object from the Flame application via the unauthenticated GET /api/config endpoint. The response contains sensitive data such as weather API keys and internal settings, enabling unauthorized use of provider quotas or illicit access to operational details.
Affected Systems
Flame, produced by pawelmalak, is affected for all releases up to and including version 2.4.0.
Risk and Exploitability
The CVSS score of 6.9 classifies this as a moderate severity flaw. Because the endpoint is unauthenticated, an attacker can exploit it simply by sending a single HTTP GET request, with no additional privileges required. EPSS is not available, and the issue is not listed in the CISA KEV catalog, which suggests limited current exploitation activity but still warrants attention.
OpenCVE Enrichment