OpenProject: Private work package subject/identity disclosure through the global Time Entries and Cost Entries APIs (linked work package rendered without visibility check)
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 4.3epss 0.2%
probabilidad de explotación
0.2%top 85% de las CVE
explotación observada
noninguna fuente lo reporta
OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/time_entries and GET /api/v3/cost_entries rendered _links.workPackage.title and _links.workPackage.href through associated_resource in modules/costs/lib/api/v3/time_entries/time_entry_representer.rb and modules/costs/lib/api/v3/cost_entries/cost_entry_representer.rb without checking WorkPackage.visible or view_work_packages, allowing users with view_time_entries or view_cost_entries to read private work package subjects and ids. This issue is fixed in 17.6.0.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Productos afectados
opf · openprojectReferencias
https://github.com/opf/openproject/commit/9e9e562e516a647f35267df715d875f58b267c18https://github.com/opf/openproject/commit/c31c2f958c8e72a0d0d748d728221d57f3ef9001https://github.com/opf/openproject/pull/23888https://github.com/opf/openproject/pull/23936https://github.com/opf/openproject/releases/tag/v17.6.0https://github.com/opf/openproject/security/advisories/GHSA-v3j7-vqwv-5w5q