PT-2023-24601 · Unknown · Openproject

Published

2023-06-01

·

Updated

2026-01-15

·

CVE-2023-33960

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenProject versions prior to 12.5.6
Description OpenProject is web-based project management software. A robots.txt file is generated to denote which routes shall or shall not be accessed by crawlers, containing project identifiers of all public projects in the instance. Even if the entire instance is marked as Login required, the /robots.txt route remains publicly available prior to version 12.5.6.
Recommendations For versions prior to 12.5.6, update to version 12.5.6 to resolve the issue. Alternatively, for versions greater than 10.0, download and apply the provided patchfile. As a temporary workaround, consider marking public projects as non-public and granting membership to those who need access to the project.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Information Disclosure

Weakness Enumeration

Related Identifiers

BIT-OPENPROJECT-2023-33960
CVE-2023-33960
GHSA-XJFC-FQM3-95Q8

Affected Products

Openproject