The vulnerability is a classic Insecure Direct Object Reference (IDOR) in the Convoy application. The root cause lies in the sources.Service.FindSourceByID function in internal/sources/impl.go. This function was responsible for fetching a 'Source' object from the database. Although the function signature included a projectID parameter, the implementation ignored it and fetched the source using only its unique id. The underlying SQL query, fetchSourceByID, also lacked a predicate to filter by project_id.
The API endpoint GET /api/v1/projects/{projectID}/sources/{sourceID}, handled by handlers.Handler.GetSource, would perform an authorization check to ensure the caller had access to the specified {projectID}. However, it then called the vulnerable FindSourceByID function. Because FindSourceByID did not enforce the project scope, an authenticated user with access to any project could craft a request using their own project ID in the URL but specify the source ID of a resource belonging to another tenant. This would bypass the authorization check and leak the target source's configuration, including sensitive plaintext credentials for message brokers like AMQP, Kafka, or SQS.
The patch, identified in commit 1cc67cd16fb1f8890cc83a3998d3f92dceb7fd06, remediates this by adding a validation step within FindSourceByID. After fetching the source by its ID, the function now explicitly checks if the ProjectID of the retrieved source matches the projectID passed in the function call, returning a 'not found' error if they do not match. This ensures that a source is only returned if it belongs to the project the user is authorized to access.