Impact
Dragonfly is an open‑source P2P‑based file distribution and image acceleration system. The vulnerability existed before version 2.4.4 in the manager/router module, where GET /api/v1/oauth and GET /api/v1/oauth/:id were registered without jwt.MiddlewareFunc() or RBAC() protection. The handler returned full OAuth records, and the model exposed the client_secret field as client_secret in JSON. When an administrator has configured a GitHub or Google OAuth provider, any unauthenticated network client could request these endpoints, retrieve the provider’s client secret, client identifier, and redirect URL. Disclosure of client_secret enables attackers to abuse the configured identity‑provider integration, subject to the provider’s redirect URI restrictions, resulting in a confidentiality breach and classification as CWE‑200, with the missing authentication requirement corresponding to CWE‑306.
Affected Systems
The vulnerability affects Dragonfly releases prior to version 2.4.4. The affected component is the manager/router under dragonflyoss:dragonfly. Administrators who have configured external OAuth providers are the ones impacted, as the insecure API exposes their Provider secrets. The feature was part of the OAuth functionality that could be utilized by any network client that can reach the manager service.
Risk and Exploitability
The CVSS score is 2.9, indicating low severity. The EPSS score is less than 1% and the issue is not listed in CISA’s KEV catalog, suggesting limited publicly known exploitation. The attack vector is straightforward: an unauthenticated HTTP GET request to the managed service, requiring network access to the Dragonfly manager. While the disclosure could allow abuse of OAuth integrations, practical exploitation may be constrained by provider‑side redirect URI restrictions. Nonetheless, the best defense remains to update to version 2.4.4 or later.
OpenCVE Enrichment
Github GHSA