VYPR

CWE-612

Improper Authorization of Index Containing Sensitive Information

BaseDraft

Description

The product creates a search index of private or sensitive documents, but it does not properly limit index access to actors who are authorized to see the original information.

Web sites and other document repositories may apply an indexing routine against a group of private documents to facilitate search. If the index's results are available to parties who do not have access to the documents being indexed, then attackers could obtain portions of the documents by conducting targeted searches and reading the results. The risk is especially dangerous if search results include surrounding text that was not part of the search query. This issue can appear in search engines that are not configured (or implemented) to ignore critical files that should remain hidden; even without permissions to download these files directly, the remote user could read them.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (11)

  • CVE-2024-25635HigFeb 19, 2024
    risk 0.57cvss 8.8epss 0.01

    alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, organization owners can view the generated API KEY and USERS of other organization owners using the `http://192.168.26.128:8080/admin/api/users/<user_id>` endpoint, which exposes the details of the…

  • CVE-2019-25605HigMar 22, 2026
    risk 0.49cvss 7.5epss 0.00

    EquityPandit 1.0 contains an insecure logging vulnerability that allows attackers to capture sensitive user credentials by accessing developer console logs via Android Debug Bridge. Attackers can use adb logcat to extract plaintext passwords logged during the forgot password…

  • CVE-2025-3653HigJan 4, 2026
    risk 0.47cvss 7.3epss 0.00

    Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an improper access control vulnerability that allows unauthorized device manipulation by accepting arbitrary serial numbers without ownership verification. Attackers can control any device by sending serial…

  • CVE-2025-3660MedJan 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains a broken access control vulnerability that allows authenticated users to access other users' pet data by exploiting missing ownership verification. Attackers can send requests to /member/pet/detailV2 with…

  • CVE-2024-49071MedDec 12, 2024
    risk 0.42cvss 6.5epss 0.01

    Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a network.

  • CVE-2022-35980HigAug 12, 2022
    risk 0.42cvss 7.5epss 0.01

    OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. Versions 2.0.0.0 and 2.1.0.0 of the security plugin are affected by an information disclosure vulnerability. Requests to an OpenSearch cluster configured with advanced access…

  • CVE-2025-3654MedJan 4, 2026
    risk 0.34cvss 5.3epss 0.00

    Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an information disclosure vulnerability that allows unauthorized access to device hardware information by exploiting insecure API endpoints. Attackers can retrieve device serial numbers and MAC addresses through…

  • CVE-2022-41918MedNov 15, 2022
    risk 0.34cvss 6.3epss 0.00

    OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. There is an issue with the implementation of fine-grained access control rules (document-level security, field-level security and field masking) where they are not correctly applied to the indices…

  • CVE-2022-22565MedApr 12, 2022
    risk 0.31cvss 4.7epss 0.00

    Dell PowerScale OneFS, versions 9.0.0-9.3.0, contain an improper authorization of index containing sensitive information. An authenticated and privileged user could potentially exploit this vulnerability, leading to disclosure or modification of sensitive data.

  • CVE-2025-57756MedAug 28, 2025
    risk 0.27cvss 5.3epss 0.00

    Contao is an Open Source CMS. In versions starting from 4.9.14 and prior to 4.13.56, 5.3.38, and 5.6.1, protected content elements that are rendered as fragments are indexed and become publicly available in the front end search. This issue has been patched in versions 4.13.56,…

  • CVE-2023-4560MedAug 28, 2023
    risk 0.00cvss 6.5epss 0.01

    Improper Authorization of Index Containing Sensitive Information in GitHub repository omeka/omeka-s prior to 4.0.4.