Impact
An Improper Access Control flaw in alf.io allows an organization owner to read system‑level configuration secrets through single configuration endpoints that require ownership. The flaw lets the attacker supply any configuration key and receive the first matching value from a lookup that includes administrator‑only data, such as the system API key. The weakness is a classic configuration‑access mis‑control (CWE‑284) and enables the disclosure of highly sensitive system secrets.
Affected Systems
The vulnerability affects alf.io versions before 2.0‑M5‑2605, owned by alfio‑event. Any installations running a pre‑2605 build are susceptible.
Risk and Exploitability
With a Medium‑High CVSS score of 7.1, this vulnerability is moderately severe. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Attackers need to possess organization‑owner privileges; once they do, they can exploit the exposed endpoints to retrieve administrator‑only configuration values. Because the flaw is purely an access‑control violation, patching is the most effective mitigation and there is no known public exploit code.
OpenCVE Enrichment