Impact
SecObserve's ApiConfigurationSerializer incorrectly leaks the basic_auth_password field from configuration responses. View-only members can retrieve decrypted passwords used by scanners or integration services via standard REST endpoints. This exposes authentication secrets that could grant attackers access to downstream systems, posing a clear confidentiality risk. The flaw maps to CWE-522.
Affected Systems
All SecObserve installations running versions prior to 1.59.1 are affected, regardless of environment.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate severity, while the EPSS score of less than 1% suggests exploitation is unlikely at present. The vulnerability is not recorded in CISA's KEV catalog. Attackers can exploit it by sending regular API requests to configuration endpoints, which is feasible for any user with view-only product access. No additional credentials or privileges are required beyond the view-only role.
OpenCVE Enrichment