Impact
In Frigate version 0.17.1 the GET /api/logs/{service} endpoint allows any authenticated user, including those with the viewer role, to download all logs that contain auto-generated admin credentials logged in query strings; an attacker can therefore recover privileged credentials breach and full control of the system, a flaw mapped to CWE-269, CWE-532, CWE-598, and CWE-863.
Affected Systems
The affected system is the Frigate open-source network video recorder by blakeblackshear, specifically the 0.17.1 release; no other vendors or products are recorded as impacted, although the risk could persist credentials until a fix is confirmed.
Risk and Exploitability
The CVSS score of 8.1 marks this flaw as high severity, yet the EPSS score of less than 1% and it is not listed in CISA’s KEV catalog; an attacker must already be authenticated, credentials are recovered the of rapid privilege escalation real even if exploitation rates are low.
OpenCVE Enrichment