CVE-2024-31402: Medium severity cybozu garoon vulnerability
Published Jun 11, 2024
·Updated
Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker to delete the data of Shared To-Dos.
Affected Software
1 affected component
Cybozu Garoon>=5.0.0<=5.15.2
Event History
Jun 11, 2024
CVE Published
via MITRE·05:21 AM
Data Sourced
via MITRE·05:21 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-31402?
CVE-2024-31402 is rated as a critical vulnerability due to its potential impact on data integrity.
2
How do I fix CVE-2024-31402?
To fix CVE-2024-31402, upgrade your Cybozu Garoon software to the latest version beyond 5.15.2.
3
Who is affected by CVE-2024-31402?
CVE-2024-31402 affects users of Cybozu Garoon versions 5.0.0 to 5.15.2.
4
What type of vulnerability is CVE-2024-31402?
CVE-2024-31402 is an incorrect authorization vulnerability that enables data deletion.
5
Can CVE-2024-31402 be exploited remotely?
Yes, CVE-2024-31402 can be exploited remotely by authenticated attackers.