Impact
Gorse releases prior to 0.5.10 expose a direct authentication bypass in the /api/dump and /api/restore endpoints. Because the system is configured with an empty administrator API key by default, attackers can invoke these protected operations without credentials. The ability to dump the entire database or overwrite it results in full confidentiality compromise of user records, items and feedback, and data integrity loss that could erase the system’s contents.
Affected Systems
The flaw affects all installations of Gorse from gorse-io that are using a version older than 0.5.10 and have not set a custom administrator API key. Users who have not overridden the default empty key are therefore exposed.
Risk and Exploitability
The severity is reflected in a CVSS score of 9.3, and the EPSS probability of 3% indicates a moderate likelihood of exploitation. The vulnerability is not catalogued in the CISA KEV list. Attackers simply need to send unauthenticated HTTP requests to the vulnerable endpoints over the network, making the attack path straightforward and remote.
OpenCVE Enrichment