Impact
Login function in Uptrace's user_handler.go can reveal sensitive information through error messages. The flaw enables an attacker to obtain details such as login failure reasons, potentially revealing usernames or other internal identifiers. This results in an information disclosure vulnerability classified under CWE‑200 and CWE‑209.
Affected Systems
Affected systems are instances of the Uptrace application with versions up to 2.1.0‑beta.8. The issue resides in the pkg/org/user_handler.go file of the Uptrace codebase, and the vulnerability is present in all released binaries up to and including this version. Users running earlier or unsupported releases are considered unaffected.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.9, indicating medium severity. EPSS is not available, and the vulnerability is not listed in CISA KEV. Attackers can trigger the flaw simply by sending remote requests to the login endpoint; the exploit is publicly disclosed and does not require privileged access. Consequently, the risk of an attacker learning internal information remains significant, especially for systems exposed to the internet.
OpenCVE Enrichment