Impact
An issue in aiflowy versions up to 2.1.2 allows a remote attacker to obtain sensitive information through the JobUtil.java module. The weakness permits unauthorized disclosure of data without authentication, representing a classic information disclosure vulnerability (CWE‑200).
Affected Systems
All installations of aiflowy with a version of 2.1.2 or earlier are vulnerable. No additional vendors or product lines are explicitly identified in the CVE report.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The EPSS score of less than 1% suggests that exploitation is unlikely in the near term. The vulnerability is not listed in the CISA KEV catalog, and no public exploits are reported. Based on the description, it is inferred that the attack vector is the network exposure of the JobUtil endpoint, allowing a remote attacker to trigger the disclosure.
OpenCVE Enrichment