OpenProject
cpe:2.3:a:openproject:openproject:*:*:*:*:*:*:*
- <= 16.6.4
- <= 17.0.0
A vulnerability in OpenProject prior to versions 17.0.1 and 16.6.5 allows users with the 'View Members' permission in any project to enumerate all groups and see their members. This issue arises from a failed permission check, enabling unauthorized visibility of group memberships.
Exploitation of this vulnerability allows for unauthorized enumeration of group memberships, revealing which users are part of specific groups.
Users can upgrade to OpenProject versions 17.0.1 or 16.6.5 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.