Impact
The vulnerability resides in a hardcoded cryptographic key used by Express Gateway. The default cipherKey, named 'sensitiveKey', is embedded in the code base. This enables any entity that can view the datastore, such as Redis, to read the encrypted OAuth 2.0 token entries, decrypt them, and retrieve valid bearer tokens that grant access to all users. The weakness allows full credential theft, impersonation, and exfiltration of data that depends on those tokens.‑coded key flaw described by CWE-1394.
Affected Systems
Any installation of Express Gateway that includes version 1.16.11 or earlier, regardless of deployment platform or container, is affected. The issue is present in the Docker image express-gateway_docker_image used for those releases. Systems that store OAuth token secrets in Redis are directly impacted; the vulnerability is tied to the default configuration of the crypto.cipherKey.
Risk and Exploitability
The CVSS base score of 7.4 indicates a high impact and a medium exploit complexity. Because the exploit requires datastore access, an attacker must first compromise or gain read permissions on the Redis instance that holds the token data. There is no publicly available exploit code, and the EPSS score is not available, which suggests limited current exploitation activity. The vulnerability is not listed in the CISA KEV catalog, yet the ability to harvest bearer tokens can allow rogue users to impersonate legitimate clients and potentially exfiltrate or manipulate protected resources.
OpenCVE Enrichment