Impact
The vulnerability resides in StackStorm’s st2 API Key handler, where an attacker can manipulate the api_key_api.user argument in st2api/st2api/controllers/v1/auth.py. This misuse leads to improper privilege management, enabling unauthorized API key operations and escalating privileges without proper authentication. Affected systems include the StackStorm St2 platform up to version 3.9.0, affecting all installations that rely on the default API Key authentication module. Risk and exploitability are moderate with a CVSS score of 5.3 and no EPSS data available. The vulnerability can be exploited remotely, and the exploit has already been disclosed publicly. The variant is not listed in the CISA KEV catalog, but the remote nature and privilege‑escalation potential warrant attention.
Affected Systems
Affected systems include the StackStorm St2 platform up to version 3.9.0, affecting all installations that rely on the default API Key authentication module.
Risk and Exploitability
Risk and exploitability are moderate with a CVSS score of 5.3 and no EPSS data available. The vulnerability can be exploited remotely, and the exploit has already been disclosed publicly. The variant is not listed in the CISA KEV catalog, but the remote nature and privilege‑escalation potential warrant attention.
OpenCVE Enrichment