Impact
The vulnerability arises from an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticated callers to reach the /metrics endpoint. Access to this endpoint exposes the server version, database client name, configured server URL, and WhatsApp instance details, resulting in moderate‑severity information disclosure as reflected by a CVSS score of 6.9.
Affected Systems
The issue affects Evolution Foundation’s evolution‑api component up to and including version 2.3.7. Any system running these affected releases is vulnerable, independent of the underlying operating system or deployment environment. The component is typically deployed as a standalone service exposing its Prometheus metrics endpoint.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. However, the lack of authentication combined with the bypass of the IP whitelist means an attacker who can reach the API’s network port can issue a simple HTTP request to /metrics and obtain sensitive data. The vulnerability is not listed in the CISA KEV catalog, but the straightforward attack path and exposed information create a non‑negligible risk for deployments that expose the metrics endpoint.
OpenCVE Enrichment