{"id":"GHSA-3j78-7m59-r7gv","summary":"Private data exposure via REST API in BuddyPress","details":"In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Authentication is not needed.\n\nThis has been patched in version 5.1.2.","aliases":["CVE-2020-5244"],"modified":"2026-07-08T06:00:43.850493142Z","published":"2020-02-24T17:18:26Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-02-24T17:18:06Z","nvd_published_at":null,"cwe_ids":["CWE-284"]},"references":[{"type":"WEB","url":"https://github.com/buddypress/BuddyPress/security/advisories/GHSA-3j78-7m59-r7gv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-5244"},{"type":"WEB","url":"https://github.com/buddypress/BuddyPress/commit/39294680369a0c992290577a9d740f4a2f2c2ca3"},{"type":"WEB","url":"https://buddypress.org/2020/01/buddypress-5-1-2"}],"affected":[{"package":{"name":"buddypress/buddypress","ecosystem":"Packagist","purl":"pkg:composer/buddypress/buddypress"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.1.2"}]}],"versions":["2.2-beta1","2.2-beta2","2.2-rc1","2.2-rc2","2.2.0","2.2.1","2.2.2","2.2.2.1","2.2.3","2.2.3.1","2.2.4","2.2.5","2.2.6","2.3.0","2.3.0-beta-2","2.3.0-beta1","2.3.0-rc1","2.3.1","2.3.2","2.3.2.1","2.3.3","2.3.4","2.3.5","2.3.6","2.3.7","2.4.0","2.4.0-beta1","2.4.0-beta2","2.4.0-rc1","2.4.2","2.4.3","2.4.4","2.4.5","2.5.0","2.5.0-beta1","2.5.0-rc1","2.5.1","2.5.2","2.5.3","2.5.4","2.5.5","2.6.0","2.6.0-beta1","2.6.0-rc1","2.6.1","2.6.1.1","2.6.2","2.6.3","2.6.4","2.7.0","2.7.0-beta1","2.7.0-rc1","2.7.0-rc2","2.7.1","2.7.2","2.7.3","2.7.4","2.7.5","2.8.0","2.8.0-RC1","2.8.0-beta1","2.8.1","2.8.2","2.9.0","2.9.0-RC1","2.9.0-beta2","2.9.1","2.9.2","2.9.3","2.9.4","2.9.5.1","3.0.0","3.0.0-RC2","3.0.0-beta1","3.0.0-beta2","3.1.0","3.2.0","3.2.1","4.0.0","4.0.0-RC1","4.0.0-beta1","4.1.0","4.2.0","4.3.0","4.4.0","4.4.1","5.0.0","5.0.0-RC1","5.0.0-RC2","5.0.0-beta1","5.0.0-beta2","5.1.0","5.1.0-beta1","5.1.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/02/GHSA-3j78-7m59-r7gv/GHSA-3j78-7m59-r7gv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N"}]}