Impact
The vulnerability allows attackers to bypass authentication when accessing the bootstrap setup endpoint in tsi-dpdp-cms. Because InterceptingFilter.java does not enforce credential checks, an attacker can invoke bootstrap functions without legitimate credentials, exposing the system to unauthorized configuration and control. The flaw exists in all releases up to version 0.5.0 and can be exploited remotely.
Affected Systems
The affected product is tsi-coop's tsi-dpdp-cms, versions older than 0.5.1. The security fix is included in release 0.5.1, which restores proper authentication enforcement on the bootstrap endpoint.
Risk and Exploitability
This issue has a CVSS score of 6.9, indicating moderate severity. The exploit is publicly available and can be launched remotely, but its EPSS score is not disclosed and it has not been listed in the CISA KEV catalog. Attackers could leverage the missing authentication to gain unauthorized access, so the risk is significant for exposed deployments.
OpenCVE Enrichment