Impact
lamp‑cloud releases through 5.10.0 expose a /defGenProject/anno/getProperties endpoint that is accessible without authentication. The endpoint returns the full JVM system property map, which includes classpath, filesystem paths, OS details, and startup secrets. This flaw, identified as CWE‑306, allows unauthenticated attackers to read sensitive information from the deployment environment.
Affected Systems
All lamp‑cloud deployments up to and including version 5.10.0 are affected. Any installation that has not applied a newer patch or configuration update is susceptible to this vulnerability.
Risk and Exploitability
With a high CVSS score of 8.7, the risk of exploitation is significant. The EPSS score is below 1%, indicating a low but non‑zero likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Because the /defGenProject/anno/getProperties endpoint is publicly reachable without authentication, attackers can reach it remotely via an HTTP POST request, harvest the full JVM property map, and disclose confidential information such as classpath, filesystem paths, operating system details, and startup secrets. The outcome is information disclosure rather than remote code execution or denial of service.
OpenCVE Enrichment