What: the CrowdSec config editor no longer lists or reads the CrowdSec account/credential files, but ExportConfig (backend/internal/api/handlers/crowdsec_handler.go) still archives the whole data directory, so an admin download of the export contains them (and the bouncer key). This is an authenticated admin feature, so it is not a vulnerability, but it is inconsistent with the editor behaviour.
Suggested approach: decide whether export should omit stored secrets (reusing the editor's hidden-file rule) or keep them for full-fidelity backups with an explicit user-facing note/option; if omitted, check that import/restore still works without them. Related: #1532 (export size).
Found while working on #1525/#1526 follow-ups. Severity: low.
What: the CrowdSec config editor no longer lists or reads the CrowdSec account/credential files, but
ExportConfig(backend/internal/api/handlers/crowdsec_handler.go) still archives the whole data directory, so an admin download of the export contains them (and the bouncer key). This is an authenticated admin feature, so it is not a vulnerability, but it is inconsistent with the editor behaviour.Suggested approach: decide whether export should omit stored secrets (reusing the editor's hidden-file rule) or keep them for full-fidelity backups with an explicit user-facing note/option; if omitted, check that import/restore still works without them. Related: #1532 (export size).
Found while working on #1525/#1526 follow-ups. Severity: low.