Impact
devpi‑server in primary or deprecated master mode permits an unauthenticated, modified GET request to the +changelog endpoint because the verify_primary check does not reject a missing identity, thus failing to require ReplicaIdentity. Consequently, the server returns the entire database contents, exposing Argon2 password hashes, devpi‑token identifiers and salts. The exposed hashes can be subject to dictionary attacks, and public tokens may help attackers derive the server secret. Large responses can also consume significant CPU, I/O capacity, and bandwidth, potentially leading to a denial‑of‑service condition.
Affected Systems
The vulnerability affects instances of devpi Server version 6.x prior to 6.20.2 and 7.x before 7.0.0b3 that are running in the primary or the deprecated master configuration. Standalone mode servers are not affected by replication, and servers that are behind nginx and use devpi‑lockdown are currently not exploitable through this vector. The attack surface is limited to servers exposing the +changelog endpoint without proper authentication enforcement.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity. The EPSS score is less than 1%, signifying a very low but nonzero probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack requires only an unauthenticated HTTP GET request to a publicly accessible +changelog URL on a server configured as primary/master, which makes it straightforward to execute from anywhere on the network or the internet. Successful exploitation allows an attacker to read full database contents, harvest password hashes, and potentially use public tokens to aid further attacks or abuse. The lack of authentication coupled with the ability to return large payloads also raises the risk of a resource exhaustion denial‑of‑service condition.
OpenCVE Enrichment
Github GHSA