Vulnerability GHSA-27c6-wp53-387x

Medium Risk
MEDIUM RISK
CVSS Score: 6.5
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
3 months ago
June 30, 2026 at 06:31 PM UTC
Nightingale exposes datasource credentials to low-privilege users
v6.0.0-beta.0 - v6.7.2
v6.0.0-beta.0 - v6.7.2

Summary

Nightingale exposes datasource credentials to low-privilege users

Details

Nightingale (n9e) before 9.0.0-beta.2 exposes full datasource configurations, including plaintext database passwords, HTTP bearer tokens, HTTP basic-auth passwords, and mTLS client keys, to any authenticated low-privilege (Standard role) user through POST /api/n9e/datasource/list. The route is registered without an admin authorization gate, unlike the sibling datasource mutation routes, and the open-source DatasourceFilter does not redact secret fields, so the secret-bearing settings, http, and auth objects are serialized in the response. The disclosed credentials enable access to the connected downstream systems.

Timeline

Published
3 months ago
June 30, 2026 at 06:31 PM UTC
Last Modified
5 hours ago
October 02, 2026 at 06:45 PM UTC