OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historical field values without enforcing object and field visibility. This vulnerability is fixed in 17.3.3 and 17.4.1.
Metrics
Affected Vendors & Products
References
History
Fri, 26 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 26 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historical field values without enforcing object and field visibility. This vulnerability is fixed in 17.3.3 and 17.4.1. | |
| Title | OpenProject: Journal diff endpoint bypasses object, journal, and field visibility checks | |
| Weaknesses | CWE-200 CWE-862 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-26T19:42:38.388Z
Reserved: 2026-05-18T22:07:37.435Z
Link: CVE-2026-47193
Updated: 2026-06-26T19:41:59.499Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-26T20:30:06Z