Impact
Missing authorization on the datasource proxy path allows an attacker to create a datasource that references a secret they cannot normally read. The attacker then induces Perses to resolve the secret, sending the decrypted value in plaintext. This results in a confidentiality breach of secrets across project and global scopes.
Affected Systems
The flaw affects the Perses application, version 0.43.0 through 0.54.0-rc.0. All installations of Perses within this range are potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity. The EPSS score is currently unavailable, so the exploitation likelihood is unknown, but the vulnerability is not yet listed in the CISA KEV catalog. Attackers with low-privilege roles that possess GlobalDatasource:create or project-level datasource creation rights can exploit the flaw by attaching a secret they cannot otherwise read. The attack requires only the ability to create or modify a datasource and does not need additional system privileges.
OpenCVE Enrichment
Github GHSA