PT-2023-24601 · Unknown · Openproject

CVE-2023-33960

·

Publicado

2023-06-01

·

Atualizado

2026-01-15

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenProject versions prior to 12.5.6
Description OpenProject is web-based project management software. A robots.txt file is generated to denote which routes shall or shall not be accessed by crawlers, containing project identifiers of all public projects in the instance. Even if the entire instance is marked as Login required, the /robots.txt route remains publicly available prior to version 12.5.6.
Recommendations For versions prior to 12.5.6, update to version 12.5.6 to resolve the issue. Alternatively, for versions greater than 10.0, download and apply the provided patchfile. As a temporary workaround, consider marking public projects as non-public and granting membership to those who need access to the project.

Exploit

Correção

Cleartext Transmission of Sensitive Information

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-OPENPROJECT-2023-33960
CVE-2023-33960
GHSA-XJFC-FQM3-95Q8

Produtos afetados

Openproject