GROWI v4.1.3 and earlier allow remote attackers to obtain information which is not allowed to access via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://github.com/weseek/growi | product third party advisory |
https://hub.docker.com/r/weseek/growi/ | product third party advisory |
https://jvn.jp/en/jp/JVN56450373/index.html | third party advisory |