Cosmos-Server Public-Devices Endpoint Vulnerability: Early Warning
An early warning has been issued regarding a vulnerability in Cosmos-Server's public-devices endpoint, which reportedly discloses Constellation device metadata to any requester supplying a non-empty Authorization header. The endpoint appears to accept arbitrary bearer tokens without validation.
What happened
The vulnerability, tracked under GHSA-5FQM-CC34-FCF5, affects Cosmos-Server version 0.22.18. This issue is under investigation, and it is recommended that users upgrade to a version that includes a fix for this vulnerability. Additionally, it is advised to review the use of the public-devices endpoint to assess potential exposure.
The Cosmos-Server team has issued an advisory on GitHub, detailing the vulnerability and recommending immediate action. Users should consult the primary sources for the most accurate and up-to-date information regarding this incident.
How 0Day mitigates this
cosmos-server is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.