Impact
The vulnerability allows GET and HEAD requests to bypass project resource permission checks, enabling users with guest or task_runner roles to retrieve entire project environments, including plaintext secrets, credentials, and passwords. This is an authorization bypass flaw classified under CWE‑862 that results in the exposure of sensitive configuration data.
Affected Systems
Semaphore UI version 2.19.12 and earlier releases are impacted. The flaw exists in the project environment API where the GetMustCanMiddleware does not enforce permission checks for GET and HEAD methods.
Risk and Exploitability
The CVSS score of 7.1 indicates medium‑to‑high severity. Attackers only need to authenticate as a guest or task_runner and then send simple HTTP GET or HEAD requests to the environment endpoint, a remote network attack path. The EPSS score of <1% suggests a very low expected exploitation probability, and the vulnerability is not currently listed in the CISA KEV catalog. Nevertheless, the ease of the attack and the value of the exposed secrets make the risk significant if the flaw remains unpatched.
OpenCVE Enrichment