CVE-2024-31400

Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.0. If this vulnerability is exploited, unintended data may be left in forwarded mail.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:cybozu:garoon:*:*:*:*:*:*:*:*

History

05 Aug 2025, 15:37

Type Values Removed Values Added
References () https://cs.cybozu.co.jp/2024/007901.html - () https://cs.cybozu.co.jp/2024/007901.html - Vendor Advisory
References () https://jvn.jp/en/jp/JVN28869536/ - () https://jvn.jp/en/jp/JVN28869536/ - Third Party Advisory
First Time Cybozu garoon
Cybozu
CPE cpe:2.3:a:cybozu:garoon:*:*:*:*:*:*:*:*

21 Nov 2024, 09:13

Type Values Removed Values Added
References () https://cs.cybozu.co.jp/2024/007901.html - () https://cs.cybozu.co.jp/2024/007901.html -
References () https://jvn.jp/en/jp/JVN28869536/ - () https://jvn.jp/en/jp/JVN28869536/ -

08 Nov 2024, 22:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-922

11 Jun 2024, 13:54

Type Values Removed Values Added
Summary
  • (es) Existe un problema de inserción de información confidencial en los datos enviados en Cybozu Garoon 5.0.0 a 5.15.0. Si se aprovecha esta vulnerabilidad, es posible que se dejen datos no deseados en el correo reenviado.

11 Jun 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-11 05:15

Updated : 2025-08-05 15:37


NVD link : CVE-2024-31400

Mitre link : CVE-2024-31400

CVE.ORG link : CVE-2024-31400


JSON object : View

Products Affected

cybozu

  • garoon
CWE
CWE-922

Insecure Storage of Sensitive Information