First published: Tue Jun 11 2024(Updated: )
Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, a user who can log in to the product may obtain information on the list of users.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Cybozu Garoon | >=5.0.0<=5.15.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31398 is considered a significant vulnerability, as it allows an unauthorized user to access sensitive information about user lists.
To mitigate CVE-2024-31398, update Cybozu Garoon to the latest version beyond 5.15.2.
CVE-2024-31398 affects all users of Cybozu Garoon versions from 5.0.0 to 5.15.2.
Exploitation of CVE-2024-31398 can lead to exposure of sensitive information regarding the list of users.
Yes, CVE-2024-31398 pertains to a vulnerability that can be exploited by any logged-in user, raising concerns about user access rights.