Impact
Harness through version 3.3.0 omits access control checks in the infrastructure provider read endpoint. This allows an authenticated user to query the GET /api/v1/infraproviders endpoint with any space identifier and retrieve sensitive provider metadata from spaces the user does not belong to. The exposed data includes Docker endpoints, TLS certificate paths, and cloud project identifiers, which could facilitate further attacks or compromise of infrastructure.
Affected Systems
The affected product is Harness, specifically version 3.3.0. Any deployment of this version is vulnerable if it exposes the infraproviders API to authenticated users without space‑level authorization checks.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact with moderate complexity. The EPSS score is below 1%, suggesting a low but non‑zero probability of exploitation at the time of analysis. The vulnerability is not listed in CISA KEV, so no known active exploit campaign is reported. Attackers would need valid user credentials but can exploit the flaw within the same application context to exfiltrate sensitive configuration information.
OpenCVE Enrichment