7.5
CVE-2026-63645
- EPSS 0.33%
- Veröffentlicht 24.09.2026 17:39:42
- Zuletzt bearbeitet 05.10.2026 16:17:14
- Erkennungen
OpenObserve: Unauthenticated /config/runtime endpoint exposes PostgreSQL database credentials
OpenObserve is a cloud-native observability platform. Prior to 0.90.3, OpenObserve registers the /config/runtime endpoint without authentication and serializes the complete server configuration after applying the hide_sensitive_fields keyword filter. The filter does not recognize dsn or creds field names, so meta_postgres_dsn, meta_postgres_ro_dsn, meta_ddl_dsn, and usage_reporting_creds can be returned in plaintext to an unauthenticated network client. PostgreSQL deployments can expose database credentials, and the same response can disclose the root administrator email address, internal NATS address, filesystem layout, and other deployment details. This issue is fixed in version 0.90.3.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstelleropenobserve
≫
Produkt
openobserve
Version
< 0.90.3
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.33% | 0.238 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
https://github.com/openobserve/openobserve/security/advisories/GHSA-v496-g5c9-vqxw
https://github.com/openobserve/openobserve/pull/12220
https://github.com/openobserve/openobserve/commit/4f3db1cf790ffe8ea065d98f87344e839ec6e477
https://github.com/openobserve/openobserve/releases/tag/v0.90.3