OpenProject是OpenProject组织开源的一个基于Web的项目管理软件。 OpenProject 17.6.0之前版本存在安全漏洞,该漏洞源于在渲染/api/v3/time_entries和/api/v3/cost_entries时未检查WorkPackage.visible或view_work_packages权限,可能导致拥有view_time_entries或view_cost_entries权限的用户读取私有工作包主题和ID。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| opf | openproject | < 17.6.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| opf | openproject | < 17.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-67527 | 7.6 HIGH | OpenProject: Improper Access Control through /api/v3/work_packages/<X.id> via PATCH parame |
| CVE-2026-67528 | 4.3 MEDIUM | OpenProject: Improper Access Control through /api/v3/custom_options/:id via Path "id" lead |
No comments yet