First published: Tue Jun 11 2024(Updated: )
Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker to delete the data of Shared To-Dos.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Cybozu Garoon | >=5.0.0<=5.15.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31402 is rated as a critical vulnerability due to its potential impact on data integrity.
To fix CVE-2024-31402, upgrade your Cybozu Garoon software to the latest version beyond 5.15.2.
CVE-2024-31402 affects users of Cybozu Garoon versions 5.0.0 to 5.15.2.
CVE-2024-31402 is an incorrect authorization vulnerability that enables data deletion.
Yes, CVE-2024-31402 can be exploited remotely by authenticated attackers.