PT-2023-24601 · Unknown · Openproject
Published
2023-06-01
·
Updated
2026-01-15
·
CVE-2023-33960
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenProject versions prior to 12.5.6
Description
OpenProject is web-based project management software. A
robots.txt file is generated to denote which routes shall or shall not be accessed by crawlers, containing project identifiers of all public projects in the instance. Even if the entire instance is marked as Login required, the /robots.txt route remains publicly available prior to version 12.5.6.Recommendations
For versions prior to 12.5.6, update to version 12.5.6 to resolve the issue.
Alternatively, for versions greater than 10.0, download and apply the provided patchfile.
As a temporary workaround, consider marking public projects as non-public and granting membership to those who need access to the project.
Exploit
Fix
Cleartext Transmission of Sensitive Information
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openproject