GHSA-4227-9989-jrhx: Perses's missing authorization in datasource proxy allows cross-scope secret disclosure
HIGHHigh-risk vulnerability
### Impact The datasource proxy authorizes the caller on the Datasource scope, then resolves and decrypts any Secret named in the request body with no Secret-scope check. Datasource and Secret are distinct, independently grantable role scopes, so an operator can grant datasource access without secret access. The proxy and the service to create a datasource does not verify that the operator has the correct right. A user holding only `GlobalDatasource:create` can create a `GlobalDatasource` and attached to it a `GlobalSecret` without having the right to get access to. …
CVE · detail
Early access
Get the next one first.
Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.
bot-protected