Impact
An authenticated participant in the VINCE system can extract the CaseStatement and per‑vulnerability CaseMemberStatus records of users belonging to another vendor. The vulnerability arises because the API checks only whether the participant belongs to the case but does not verify ownership of the requested member identifier. Consequently, confidential or embargoed statement text and vendor‑specific metadata can be retrieved by anyone who is logged in as a case participant, enabling a data breach that crosses organizational boundaries.
Affected Systems
The flaw exists in the CERT/CC VINCE platform. No specific version information was provided, but the issue was identified in the code reference of the VINCE repository.
Risk and Exploitability
The attack requires only authentication as a case participant and can be performed through a normal API call. The CVSS score of 6.5 reflects a moderate severity, and the EPSS score of <1% indicates a very low exploitation probability. VINCE is not listed in the CISA KEV catalog, yet the impact on confidentiality is severe. The vulnerability can be exploited by any user who has legitimate credentials and can simply provide the target member’s identifier. Official fixes are pending; a patch has been submitted in pull request 235.
OpenCVE Enrichment