CVE-2024-31398: Medium severity cybozu garoon vulnerability
Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, a user who can log in to the product may obtain information on the list of users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31398?
CVE-2024-31398 is considered a significant vulnerability, as it allows an unauthorized user to access sensitive information about user lists.
How do I fix CVE-2024-31398?
To mitigate CVE-2024-31398, update Cybozu Garoon to the latest version beyond 5.15.2.
Who is affected by CVE-2024-31398?
CVE-2024-31398 affects all users of Cybozu Garoon versions from 5.0.0 to 5.15.2.
What kind of information can be exposed by CVE-2024-31398?
Exploitation of CVE-2024-31398 can lead to exposure of sensitive information regarding the list of users.
Is CVE-2024-31398 related to user access rights?
Yes, CVE-2024-31398 pertains to a vulnerability that can be exploited by any logged-in user, raising concerns about user access rights.