Impact
The vulnerability in CodexBar version 0.32 or earlier allows an attacker who can influence HTTP redirects to cause the application’s shared ProviderHTTPClient to forward authentication credentials to an unintended endpoint. Because the redirect can target a host, port, or plain HTTP URL, the browser’s stored cookies, bearer tokens or API keys are transmitted unprotected, exposing them to the attacker. This credential leakage can lead to unauthorized access to the targeted service or other systems that rely on those credentials.
Affected Systems
Affected vendors and products include steipete:CodexBar with any release older than 0.33.0. Specific version ranges are not provided beyond the major update noted, so all versions before the 0.33.0 release are vulnerable. Users running these versions on network‑adjacent or shared environments are at risk.
Risk and Exploitability
The CVSS score of 6 indicates a moderate severity. No EPSS score is available, but the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. Nevertheless, an attacker with local network or privileged access could craft a cross‑origin HTTP redirect or downgrade attack to capture credentials. The lack of secure transport enforcement makes the vulnerability exploitable in any environment allowing the attacker to force a redirect.
OpenCVE Enrichment