In Internet2 Grouper 5.17.1 before 5.20.5, group admins who are not Grouper sysadmins can configure loader jobs.
References
Configurations
History
08 Oct 2025, 16:24
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:internet2:grouper:*:*:*:*:*:*:*:* | |
| First Time |
Internet2 grouper
Internet2 |
|
| References | () https://spaces.at.internet2.edu/display/Grouper/Grouper+bug+-+GRP-6311+-+non-Grouper-admins+can+configure+loader+jobs - Vendor Advisory |
19 Sep 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://spaces.at.internet2.edu/display/Grouper/Grouper+bug+-+GRP-6311+-+non-Grouper-admins+can+configure+loader+jobs - |
19 Sep 2025, 03:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-09-19 03:15
Updated : 2025-10-08 16:24
NVD link : CVE-2025-59714
Mitre link : CVE-2025-59714
CVE.ORG link : CVE-2025-59714
JSON object : View
Products Affected
internet2
- grouper
CWE
CWE-863
Incorrect Authorization
