CVE-2024-31404: Medium severity cybozu garoon vulnerability
Published Jun 11, 2024
·Updated
Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.5.0 to 6.0.0, which may allow a user who can log in to the product to view the data of Scheduler.
Affected Software
2 affected components
Cybozu Garoon>=5.5.0<=6.0.0
Cybozu Garoon>=5.5.0<6.0.1
Event History
Jun 11, 2024
CVE Published
via MITRE·04:27 AM
Data Sourced
via MITRE·04:27 AM
DescriptionWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-31404?
CVE-2024-31404 has been classified as a medium severity vulnerability due to the potential exposure of sensitive information.
2
How do I fix CVE-2024-31404?
To fix CVE-2024-31404, update Cybozu Garoon to the latest version that corrects this issue.
3
What versions of Cybozu Garoon are affected by CVE-2024-31404?
CVE-2024-31404 affects Cybozu Garoon versions 5.5.0 through 6.0.0.
4
What type of information can be exposed due to CVE-2024-31404?
CVE-2024-31404 can expose scheduler-related data, allowing users to view sensitive information.
5
Is authentication required to exploit CVE-2024-31404?
Yes, exploitation of CVE-2024-31404 requires a user to be logged in to the Cybozu Garoon product.