Impact
PagerDuty alarm hook transmits the integration routing key over cleartext HTTP. The initial POST containing the JSON body with the routing key is written to the socket unencrypted before any redirect to HTTPS occurs. This exposes the key to anyone able to capture traffic on the network. Based on the description, it is inferred that an attacker who intercepts the initial unsecured HTTP request could obtain a credential that authenticates to PagerDuty, potentially allowing creation or modification of alerts and compromising the integrity of the integration configuration.
Affected Systems
Apache SkyWalking, distributed by the Apache Software Foundation, versions 9.6.0 through 11.0.0 are affected when configured to use PagerDuty alarm hooks.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is <1% and the vulnerability is not listed in CISA KEV, suggesting a low likelihood of widespread exploitation. However, based on the description, it is inferred that the primary attack vector involves network interception of the initial unencrypted HTTP POST; any environment permitting outbound HTTP traffic to PagerDuty without proper isolation is at risk.
OpenCVE Enrichment