Skip to main content

Exposure of Sensitive Information Through Metadata

CVE-2025-13084

Severity Medium
Score 6.1/10

Summary

The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys. This endpoint requires an Editor role to access and will display API keys for all users, including Administrators.

  • LOW
  • NETWORK
  • LOW
  • UNCHANGED
  • NONE
  • LOW
  • HIGH
  • LOW

CWE-1230 - Exposure of Sensitive Information Through Metadata

The product prevents direct access to a resource containing sensitive information, but it does not sufficiently limit access to metadata that is derived from the original, sensitive information.

References

Advisory Timeline

  • Published