Impact
Cap-go before version 12.128.2 contains an information disclosure flaw in the public.transfer_app RPC function. The function returns different error messages depending on whether the supplied app ID exists. An unauthenticated attacker can therefore enumerate valid app IDs by observing these error responses when supplying only the publishable API key. The vulnerability enables discovery of active app identifiers, revealing organizational deployment details. Based on the description, a preliminary step to more targeted attacks and compromises confidentiality of the app catalog.
Affected Systems
Cap-go's Cap-go product, versions before 12.128.2, is affected. The flaw resides in the public.transfer_app RPC function that only requires a publishable API key.
Risk and Exploitability
The CVSS score of 6.9 signals a medium severity impact. This assessment reflects the lack of code execution in the exploit and the requirement for only unauthenticated RPC access to leverage the oracle. The EPSS score of less than 1% indicates that exploitation is considered unlikely at present, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers could potentially reach the vulnerable endpoint over a remote network if it is exposed, making the attack vector remote.
OpenCVE Enrichment