Impact
The vulnerability is due to a missing authorization check on the GET /user/teams/:id endpoint in Yao through v1.0.0-rc22. Any authenticated user can specify a team identifier and retrieve full details about that team—including name, description, owner information, and settings—without verifying membership. This results in unauthorized disclosure of internal team data (CWE-862).
Affected Systems
The flaw affects YaoApp's Yao application, specifically version 1.0.0-rc22 and any earlier releases that contain the unpatched code. Users should verify the version they are running to determine if the vulnerability applies.
Risk and Exploitability
The CVSS score of 5.3 reflects a moderate risk; exploitation requires only authentication, which can be achieved with a legitimate user account or a compromised one. The EPSS score of < 1% indicates a very low likelihood of active exploitation in the wild, and the vulnerability is not listed in CISA's KEV catalog. Nonetheless, the ability to read detailed team information from any authenticated session raises the potential for internal data leakage and warrants timely remediation.
OpenCVE Enrichment