Impact
The vulnerability resides in Steeltoe's Management.Endpoint. When the HttpExchanges actuator is enabled together with the IncludeQueryString setting, recorded request URIs are returned verbatim through a masking helper that does not filter the query string. Attackers who can reach the /actuator/httpexchanges endpoint may receive OAuth tokens, password‑reset tokens, signed‑URL signatures, API keys, and other secrets that were present in prior traffic, leading to exposure of privileged credentials. The same data may also appear in DEBUG‑level logs, creating an additional leak channel for users with log access.
Affected Systems
The flaw affects Steeltoe OSS projects, specifically any application using a Steeltoe.Management.Endpoint version earlier than 4.3.0 that exposes the /actuator/httpexchanges endpoint with the IncludeQueryString option enabled. Versions 4.3.0 and newer contain the fix and no longer expose this data.
Risk and Exploitability
The CVSS base score is 5.9, classifying the risk as medium. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Exploitation requires network visibility to the actuator endpoint and the IncludeQueryString option to be true. If internal users or external attackers can query /actuator/httpexchanges, they can retrieve stored query strings that may contain confidential tokens, leading to credential compromise. The attack vector is therefore an HTTP request to a publicly or internally reachable actuator URI.
OpenCVE Enrichment
Github GHSA