Lucene search

K
vulnrichmentJpcertVULNRICHMENT:CVE-2024-31398
HistoryJun 11, 2024 - 5:20 a.m.

CVE-2024-31398

2024-06-1105:20:51
jpcert
github.com
1
cybozu garoon
sensitive information
data insertion
user list
cve-2024-31398

6.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, a user who can log in to the product may obtain information on the list of users.

CNA Affected

[
  {
    "vendor": "Cybozu, Inc.",
    "product": "Cybozu Garoon",
    "versions": [
      {
        "status": "affected",
        "version": "5.0.0 to 5.15.2"
      }
    ]
  }
]

6.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Related for VULNRICHMENT:CVE-2024-31398