Description
Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /updates endpoint that resolves the defaultChannel parameter before enforcing privacy restrictions, allowing attackers to enumerate private channels and leak version/config state. Unauthenticated attackers can probe private channel names and distinguish valid channels from nonexistent ones based on response differences, revealing assigned bundle versions and platform-specific configuration details.
Problem types
Exposure of Sensitive Information to an Unauthorized Actor
Product status
Any version before 12.128.2
12.128.2 (semver)
Credits
Judel777
References
github.com/.../capgo/security/advisories/GHSA-pgmr-gw53-7f77
github.com/.../capgo/security/advisories/GHSA-pgmr-gw53-7f77 (GitHub Security Advisory (GHSA-pgmr-gw53-7f77))
www.vulncheck.com/...icated-updates-defaultchannel-parameter (VulnCheck Advisory: Capgo - Information Disclosure via Unauthenticated /updates defaultChannel Parameter)