Impact
The vulnerability allows any authenticated member of a project who is not an administrator to retrieve the inplace‑edit dialog for a custom field. The dialog resolves the field by its raw identifier and does not enforce the normal admin‑only visibility constraint. Consequently, the comment stored with the field is displayed in read‑only mode, exposing hidden comment text. The custom‑field value itself remains protected, and no write or mutation is possible.
Affected Systems
Affected systems are installations of OpenProject version 17.5.1 and earlier. The issue is fixed in v17.6.0, which restores proper visibility enforcement for admin‑only custom fields.
Risk and Exploitability
The CVSS v3.1 score of 5.3 indicates moderate severity, and the vulnerability is not listed in CISA KEV and has no EPSS data. Based on the description, it is inferred that the attack vector is through legitimate application use as an authenticated non‑admin project member. While it does not provide privilege escalation or code execution, the feasible exploitation yields unintended disclosure of confidential comment content to users not authorized to see it.
OpenCVE Enrichment