GHSA-mrqp-7v92-wchjHighCVSS 8.8

Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token...

Published
September 1, 2026
Last Modified
September 1, 2026

🔗 CVE IDs covered (1)

📋 Description

Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated account can query the endpoint with arbitrary project, environment, and application parameters to retrieve plaintext super-admin JWT tokens for full platform control.

🔗 References (7)