GHSA-8x2m-938h-j94gHighCVSS 7.5
A flaw was found in search-v2-api. The authentication middleware in the affected component...
🔗 CVE IDs covered (1)
📋 Description
A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authentication when a request includes an Upgrade: websocket header. An unauthenticated attacker can exploit this by sending a specially crafted HTTP POST request to the /federated endpoint with the Upgrade: websocket header. This allows the attacker to bypass authentication and access federated search results across all configured remote managed hubs, leading to information disclosure.