Impact
canto‑saas‑api discloses OAuth2 credentials by placing app_id, app_secret, refresh_token, and code in the URL query string of token POST requests and by including the full request URI in AuthorizationFailedException when token acquisition fails. The leaked data can be captured in web access logs, proxy logs, and APM traces. An attacker who can read these telemetry records can retrieve the credentials and use them to obtain access tokens for the tenant, exposing all authenticated sessions. This is an example of information‑exposure weaknesses (CWE‑598 and CWE‑209).
Affected Systems
All releases of canto‑saas‑api before version 3.0.0 are affected. Versions 3.0.0 and later contain the fix and are no longer vulnerable.
Risk and Exploitability
The CVSS score is 5.3, and the EPSS score of < 1 % indicates a very low probability that the vulnerability will be exploited in the wild. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires access to application logs or error‑tracking systems, so environments with exposed or publicly readable logs pose a higher risk, although current exploitation activity remains limited.
OpenCVE Enrichment
Github GHSA