Cosmos-Server's Public-Devices Endpoint Discloses Metadata
An early warning has been issued regarding Cosmos-Server's public-devices endpoint, which reportedly discloses device metadata to any requester that supplies a non-empty Authorization header. The endpoint appears to accept arbitrary bearer tokens without validation.
What happened
The Cosmos-Server's constellation public-devices endpoint is under investigation for disclosing Constellation device metadata to any requester that supplies a non-empty Authorization header. The endpoint is reported to accept arbitrary bearer tokens without validation, potentially allowing unauthorized access to device metadata. Affected versions include cosmos-server (go) version 0.22.18. It is recommended to review the usage of the public-devices endpoint for potential unauthorized access and to upgrade to a fixed version of cosmos-server once available. For more details, consult the primary sources: [GHSA-2rx5-2g7j-2659](https://github.com/azukaar/Cosmos-Server/security/advisories/GHSA-2rx5-2g7j-2659) and [GHSA-5fqm-cc34-fcf5](https://github.com/azukaar/Cosmos-Server/security/advisories/GHSA-5fqm-cc34-fcf5).
How 0Day mitigates this
cosmos-server is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.