{"id":"CVE-2022-41799","details":"Improper access control vulnerability in GROWI prior to v5.1.4 (v5 series) and versions prior to v4.5.25 (v4 series) allows a remote authenticated attacker to bypass access restriction and download the markdown data from the pages set to private by the other users.","modified":"2026-03-14T11:56:07.048378Z","published":"2022-10-24T14:15:52.687Z","references":[{"type":"ADVISORY","url":"https://jvn.jp/en/jp/JVN00845253/index.html"},{"type":"ADVISORY","url":"https://weseek.co.jp/en/news/2022/10/07/growi-private-page-can-be-viewed/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/weseek/growi","events":[{"introduced":"07d839f0b213a064e90cc9166914e4444d4bd49c"},{"fixed":"b830eb662cac28d7d8b404896359ace8e595a27e"},{"introduced":"424a25b0542d671724d86ef062b398564161574a"},{"fixed":"5de6f2fa77779caaaafa258197af38d0667998e0"}],"database_specific":{"versions":[{"introduced":"4.0.0"},{"fixed":"4.5.25"},{"introduced":"5.0.0"},{"fixed":"5.1.4"}]}}],"versions":["v5.0.0","v5.0.1","v5.0.10","v5.0.11","v5.0.2","v5.0.3","v5.0.4","v5.0.5","v5.0.6","v5.0.7","v5.0.8","v5.0.9","v5.1.0","v5.1.1","v5.1.2","v5.1.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-41799.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}