Impact
The vulnerability allows a user with the "ROLE_USER" role to retrieve the internal service account API key via the pipeline endpoint. The disclosed key can be used to impersonate the internal service account, bypass normal rate limits, and anonymously access sensitive internal endpoints that expose all requests and load information, thereby compromising confidentiality and integrity of the application data. The weakness is a classic information exposure flaw (CWE‑200) coupled with poor secret management (CWE‑522).
Affected Systems
Stirling‑Tools’s Stirling‑PDF application, versions prior to 2.9.0, is affected. The flaw resides in the /api/v1/pipeline/handleData endpoint within PipelineProcessor.java and allows attackers to retrieve the STIRLING‑PDF‑BACKEND‑API‑USER key and subsequently access internal routes such as /api/v1/info/requests/all and /api/v1/info/load/all.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity vulnerability that can lead to significant exposure of sensitive data. The EPSS score is not available, so the exploitation probability is uncertain, but the nature of the flaw—an API key disclosure that enables impersonation and unrestricted access—makes it an attractive target for attackers. Because the vulnerability is listed outside the CISA KEV catalog, it may not yet be actively exploited, yet the potential for internal compromise warrants urgent attention.
OpenCVE Enrichment