GHSA-6xgx-xx3m-pg85MediumCVSS 6.5
An information disclosure vulnerability in Windmill Labs Windmill through 1.783.0 allows any...
🔗 CVE IDs covered (1)
📋 Description
An information disclosure vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace member to read legacy ownerless draft scripts that contain plaintext resource credentials. Drafts with a null owner email bypass ACL enforcement and are returned to any workspace member who queries the drafts endpoint. Sensitive credentials stored in these drafts are exposed across ACL boundaries.