Impact
A flaw in the AssumeRole handler allows an attacker to supply a crafted external_id value, causing the component to grant permissions that it should not. This incorrect permission assignment can elevate privileges and allow unauthorized access to resources.
Affected Systems
The vulnerability affects devopspolis secrets‑replicator versions up to 0.4.0. Packages marked with the devopspolis:secrets‑replicator identifier are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 classifies the issue as medium severity. No EPSS score is published and the vulnerability is not currently listed in CISA KEV. The flaw can be exploited remotely, likely via API calls that include the manipulated external_id parameter. Because the flaw is not a code execution path, the risk primarily involves improper authorization rather than a broader compromise.
OpenCVE Enrichment