In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Authentication is not needed. This has been patched in version 5.1.2.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-0286 | In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Authentication is not needed. This has been patched in version 5.1.2. |
Github GHSA |
GHSA-3j78-7m59-r7gv | Private data exposure via REST API in BuddyPress |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-04T08:22:09.059Z
Reserved: 2020-01-02T00:00:00.000Z
Link: CVE-2020-5244
No data.
Status : Modified
Published: 2020-02-24T18:15:22.400
Modified: 2024-11-21T05:33:45.183
Link: CVE-2020-5244
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA