PT-2023-24601 · Unknown · Openproject
CVE-2023-33960
·
Publicado
2023-06-01
·
Atualizado
2026-01-15
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenProject versions prior to 12.5.6
Description
OpenProject is web-based project management software. A
robots.txt file is generated to denote which routes shall or shall not be accessed by crawlers, containing project identifiers of all public projects in the instance. Even if the entire instance is marked as Login required, the /robots.txt route remains publicly available prior to version 12.5.6.Recommendations
For versions prior to 12.5.6, update to version 12.5.6 to resolve the issue.
Alternatively, for versions greater than 10.0, download and apply the provided patchfile.
As a temporary workaround, consider marking public projects as non-public and granting membership to those who need access to the project.
Exploit
Correção
Cleartext Transmission of Sensitive Information
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Openproject