PT-2025-38504 · Internet2 · Grouper

Chris Hyzer

·

Published

2025-09-19

·

Updated

2025-09-19

·

CVE-2025-59714

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Internet2 Grouper versions 5.17.1 through 5.20.4
Description Group administrators who are not also Grouper system administrators can configure loader jobs.
Recommendations Update to a version prior to 5.17.1 or after 5.20.5.

Exploit

Fix

LPE

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-59714

Affected Products

Grouper