Impact
Cosmos servers use a token middleware that, in earlier releases, returned a request through the Constellation tunnel before clearing the user‑identifying headers (x-cosmos-user, x-cosmos-role, x-cosmos-user-role, x-cosmos-mfa) and before executing the AdminOnlyWithRedirect check. An attacker possessing a valid x‑cstln‑auth API key for an enrolled device can supply a chosen x‑cosmos-user header to a route configured with AuthEnabled. If the upstream application trusts this forward‑auth header, Cosmos fails to perform its own JWT, password, MFA, and admin‑only validation, enabling the attacker to impersonate any user or gain administrative access to resources behind the proxy. The issue was fixed in version 0.22.19.
Affected Systems
The affected product is Cosmos‑Server from azukaar, with vulnerable releases older than version 0.22.19. Users running any 0.22.18 or earlier build are susceptible.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.1, indicating a moderate severity, and it is not yet listed in CISA’s KEV catalog. Because the exploit requires a valid x‑cstln‑auth key for an enrolled device and so‑called Constellation Nebula tunnel access, the attack vector is highly targeted and inferred to be internal or within trusted networks. The EPSS score is < 1%, indicating a very low exploitation probability, yet the potential for user impersonation and admin data exposure makes it a serious concern for affected deployments.
OpenCVE Enrichment
Github GHSA