CVE-2019-5978: Medium severity cybozu garoon vulnerability
Published Sep 12, 2019
·Updated
Open redirect vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the application 'Scheduler'.
Affected Software
1 affected component
Cybozu Garoon>=4.0.0<=4.10.2
Event History
Sep 12, 2019
CVE Published
via MITRE·03:58 PM
Data Sourced
via MITRE·03:58 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-5978?
CVE-2019-5978 is considered medium severity due to its potential for facilitating phishing attacks.
2
How do I fix CVE-2019-5978?
To fix CVE-2019-5978, upgrade Cybozu Garoon to version 4.10.3 or later, which addresses the open redirect vulnerability.
3
Which versions of Cybozu Garoon are affected by CVE-2019-5978?
CVE-2019-5978 affects Cybozu Garoon versions from 4.0.0 to 4.10.2.
4
What kind of attacks can CVE-2019-5978 allow?
CVE-2019-5978 can allow remote attackers to conduct phishing attacks by redirecting users to arbitrary websites.
5
Is there a workaround for CVE-2019-5978?
There are no documented workarounds for CVE-2019-5978; updating to a patched version is recommended.