PT-2024-26079 · Unknown · Group Sharing

Published

2024-09-03

·

Updated

2024-09-05

·

CVE-2024-34659

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GroupSharing versions prior to 13.6.13.3
Description The issue allows remote attackers to force victims to join a group, resulting in exposure of sensitive information. This can be achieved by exploiting the vulnerability in GroupSharing.
Recommendations For versions prior to 13.6.13.3, upgrade to version 13.6.13.3 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information within GroupSharing until the upgrade is applied.

Fix

Related Identifiers

CVE-2024-34659

Affected Products

Group Sharing