Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🐍
🐍 PyPI
Not in CISA KEV
MEDIUM severity

GHSA-rcvg-jj3g-rj7c — ethyca-fides

MEDIUM

GHSA-rcvg-jj3g-rj7c is a medium-severity (CVSS 6.5) Information Exposure vulnerability in ethyca-fides. A fix is available for ethyca-fides — see the affected versions and patch details below.

Sensitive Data Disclosure Vulnerability in Connection Configuration Endpoints

Also known asCVE-2024-35189PYSEC-2026-1346
Published
Jun 2, 2024
Updated
Sep 10, 2026
Affected
1 pkg
Patched
1 / 1
Exploits
None indexed
Exploitation data as of Sep 24, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

Proof-of-concept exploit code exists

  • CISA’s SSVC triage found public proof-of-concept exploit code for this CVE, though no confirmed active exploitation.

Exploitation and automatability from CISA’s SSVC triage for GHSA-rcvg-jj3g-rj7c.

EPSS Exploitation Probability

via FIRST.org ↗
0.6%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs45th percentile — riskier than 45% of all scored CVEsHighest risk

EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.

How urgent is this, really

GHSA-rcvg-jj3g-rj7c plotted by exploitation likelihood (EPSS) against impact (CVSS). The shaded corner — EPSS 50%+ and CVSS 7.0+ — is where this CVE doesn't sit, though severity or exploitability alone can still warrant action.

Where this sits among everything scored

Of 378,156 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Real counts from FIRST.org, not a sample — log-scaled since the landscape is heavily right-skewed.

Real-World Exposure

1 pkg affected
🐍ethyca-fides

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects PyPI packages — download data is not available via public APIs for these ecosystems.

Description

The Fides webserver has a number of endpoints that retrieve ConnectionConfiguration records and their associated secrets which can contain sensitive data (e.g. passwords, private keys, etc.). These secrets are stored encrypted at rest (in the application database), and the associated endpoints are not meant to expose that sensitive data in plaintext to API clients, as it could be compromising.

Fides's developers have available to them a Pydantic field-attribute (sensitive) that they can annotate as True to indicate that a given secret field should not be exposed via the API. The application has an internal function that uses sensitive annotations to mask the sensitive fields with a "**********" placeholder value.

This vulnerability is due to a bug in that function, which prevented sensitive API model fields that were nested below the root-level of a secrets object from being masked appropriately. Only the BigQuery connection configuration secrets meets these criteria: the secrets schema has a nested sensitive keyfile_creds.private_key property that is exposed in plaintext via the APIs.

Connection types other than BigQuery with sensitive fields at the root-level that are not nested are properly masked with the placeholder and are not affected by this vulnerability.

Impact

The Google Cloud secrets used for a Fides BigQuery integration may be retrieved in plaintext by any authenticated Admin UI user, except those with the Approver role. Any API users authorized to access the following endpoints may also retrieve the key in plaintext.

Endpoints impacted:

  • GET /api/v1/connections
  • PATCH /api/v1/connections
  • GET /api/v1/connection/{connection_key}
  • PATCH /api/v1/system/{system_key}/connection
  • GET /api/v1/system/{system_key}
  • GET /api/v1/system/{system_key}/connection

Connection config secret schemas impacted:

  • BigQuerySchema

Patches

The vulnerability has been patched in Fides version 2.37.0. Users are advised to upgrade to this version or later to secure their systems against this threat.

Users are also advised to rotate any Google Cloud secrets used for BigQuery integrations in their Fides deployments: https://cloud.google.com/iam/docs/key-rotation

Workarounds

There are no workarounds.

Proof of concept

Multiple endpoints are impacted, but this PoC will use GET /api/v1/system/{system_key} as an example.

  1. Using the Admin UI, navigate to /add-systems. Add and save a new system bq_poc.
  2. In the integrations tab of the new system, configure and save a BigQuery integration with secrets.
  3. Log in as a different user with any role except Approver and navigate to the /systems page.
  4. Open the network section of your browser's developer tools.
  5. Click on the bq_poc system's meatball menu and then click edit.
  6. In the network section of browser dev tools you will observe a HTTP GET http://localhost:8080/api/v1/system/bq_poc/ request. In the body of the JSON response the integration secrets values entered in Step 2 are exposed in plaintext i.e.
{
  "secrets": {
    "keyfile_creds": {
      "type": "value",
      "project_id": "value",
      "private_key_id": "value",
      "private_key": "value",
      "client_email": "value",
      "client_id": "value",
      "auth_uri": "value",
      "token_uri": "value",
      "auth_provider_x509_cert_url": "value",
      "client_x509_cert_url": "value"
    }
  }
}

Affected Packages

1 total 1 fixed
EcosystemPackageVulnerable rangeFix
🐍PyPIethyca-fidesall versions2.37.0pip install --upgrade 'ethyca-fides==2.37.0'

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for ethyca-fides, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update ethyca-fides to 2.37.0 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-rcvg-jj3g-rj7c is resolved across your whole dependency graph.

  3. Workarounds

    If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.

  4. How O3 protects you

    O3 Security's impact-aware SCA analyses which vulnerable code paths your application actually calls, so a match like GHSA-rcvg-jj3g-rj7c can be triaged on real exposure rather than presence alone.

Tailored to GHSA-rcvg-jj3g-rj7c. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.

Frequently Asked Questions

The Fides webserver has a number of endpoints that retrieve `ConnectionConfiguration` records and their associated `secrets` which _can_ contain sensitive data (e.g. passwords, private keys, etc.). These `secrets` are stored encrypted at rest (in the application database), and the associated endpoints are not meant to expose that sensitive data in plaintext to API clients, as it could be compromising. Fides's developers have available to them a Pydantic field-attribute (`sensitive`) that they can annotate as `True` to indicate that a given secret field should not be exposed via the API. The
O3 Security · Impact-Aware SCA

Is GHSA-rcvg-jj3g-rj7c in your dependencies?

O3 Security finds GHSA-rcvg-jj3g-rj7c across PyPI dependencies, including transitive ones, and its impact-aware SCA ranks findings by whether your code actually calls the vulnerable path.

GHSA-rcvg-jj3g-rj7c: Medium 6.5 severity | O3 Security