Impact
The vulnerability allows an authenticated user with only viewer permissions to supply a different project identifier in the query parameters of project-scoped list endpoints such as /api/v1/projects/{project}/dashboards and /api/v1/datasources. The API then selects dashboards, data sources, and variables for the supplied project without checking whether the caller is authorized to view that project. The result is that complete resource specifications belonging to other projects are exposed to users who should not have access, violating confidentiality and tenant isolation as defined by CWE‑639.
Affected Systems
Open‑source observability dashboard and visualization platform Perses is affected. Any instance running a version earlier than 0.54.0‑beta.3, including 0.53.x and other older releases, contains the flaw because the authorization check was added only in 0.54.0‑beta.3.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity flaw. The EPSS score is not available, so the likelihood of exploitation is uncertain, but the fact that an attacker only needs viewer credentials to trigger the bypass makes the risk substantial. The vulnerability is currently not listed in CISA’s KEV catalog. Attackers can exploit the flaw by authenticating with any viewer account, appending a different project ID to the API query, and retrieving resources from other projects. Immediate remediation is advised to prevent cross-project data leakage.
OpenCVE Enrichment
Github GHSA