VulnerabilityModified
CVE-2014-0820
Directory traversal vulnerability in the download feature in Cybozu Garoon 2.x through 2.5.4 and 3.x through 3.7 SP3 allows remote authenticated users to read arbitrary files via unspecified vectors.
MEDIUM 4.0EPSS 1.49%
Does this matter?
Lower severity and a low EPSS score (1.49%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in the download feature in Cybozu Garoon 2.x through 2.5.4 and 3.x through 3.7 SP3 allows remote authenticated users to read arbitrary files via unspecified vectors.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
- EPSS
- 1.49% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- cybozu/garoon
- Source
- vultures@jpcert.or.jp
References
- http://cs.cybozu.co.jp/information/gr20140225up05.phpVendor Advisory
- http://jvn.jp/en/jp/JVN26393529/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2014-000023Vendor Advisory
- http://www.securityfocus.com/bid/65815
- https://support.cybozu.com/ja-jp/article/7994Vendor Advisory
- http://cs.cybozu.co.jp/information/gr20140225up05.phpVendor Advisory
- http://jvn.jp/en/jp/JVN26393529/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2014-000023Vendor Advisory
- http://www.securityfocus.com/bid/65815
- https://support.cybozu.com/ja-jp/article/7994Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.