CVE-2019-5933

MEDIUM

Cybozu Garoon 4.0.0-4.10.0 - Authenticated Access Restriction Bypass via Bulletin Application

Title source: llm
STIX 2.1

Description

Cybozu Garoon 4.0.0 to 4.10.0 allows remote authenticated attackers to bypass access restriction to view the Bulletin Board without view privileges via the application 'Bulletin'.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
http://jvn.jp/en/jp/JVN58849431/index.html
Vendor Advisory x_refsource_misc
https://kb.cybozu.support/article/35307/

Scores

CVSS v3 4.3
EPSS 0.0015
EPSS Percentile 35.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

Status published
Products (1)
cybozu/garoon 4.0.0 - 4.10.0
Published May 17, 2019
Tracked Since Feb 18, 2026