{"id":"CVE-2022-41799","details":"Improper access control vulnerability in GROWI prior to v5.1.4 (v5 series) and versions prior to v4.5.25 (v4 series) allows a remote authenticated attacker to bypass access restriction and download the markdown data from the pages set to private by the other users.","modified":"2026-08-27T03:50:42.716336626Z","published":"2022-10-24T00:00:00Z","database_specific":{"cna_assigner":"jpcert","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/41xxx/CVE-2022-41799.json","unresolved_ranges":[{"extracted_events":[{"introduced":"versions prior to v5.1.4 (v5 series) and versions prior to v4.5.25 (v4 series)"},{"last_affected":"versions prior to v5.1.4 (v5 series) and versions prior to v4.5.25 (v4 series)"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://jvn.jp/en/jp/JVN00845253/index.html"},{"type":"WEB","url":"https://weseek.co.jp/en/news/2022/10/07/growi-private-page-can-be-viewed/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/41xxx/CVE-2022-41799.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-41799"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/growilabs/growi","events":[{"introduced":"07d839f0b213a064e90cc9166914e4444d4bd49c"},{"fixed":"b830eb662cac28d7d8b404896359ace8e595a27e"},{"introduced":"424a25b0542d671724d86ef062b398564161574a"},{"fixed":"5de6f2fa77779caaaafa258197af38d0667998e0"}],"database_specific":{"cpe":"cpe:2.3:a:weseek:growi:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.0.0"},{"fixed":"4.5.25"},{"introduced":"5.0.0"},{"fixed":"5.1.4"}],"source":"CPE_RANGE"}}],"versions":["v5.1.3","v5.1.2","v5.0.11","v5.1.1","v5.1.0","v5.0.10","v5.0.9","v5.0.8","v5.0.7","v5.0.6","v5.0.5","v5.0.4","v5.0.3","v5.0.2","v5.0.1","v5.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-41799.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"}]}