Impact
This vulnerability occurs because OpenCVE versions before 3.1.0 do not correctly enforce the organization scope of the API token. When a token is created with a specific organization scope, the organizations endpoint still returns all of the token creator’s memberships, allowing the bearer to discover and retrieve data about every organization the token’s owner belongs to. The impact is the exposure of sensitive organizational membership information and the potential for further downstream compromise if those organizations contain critical resources.
Affected Systems
The affected product is OpenCVE, specifically all releases older than version 3.1.0. Users running v2.4.0 or any earlier build will be vulnerable, as the fix was introduced in the 3.1.0 release. No other vendors or products are impacted according to the CNA data.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% suggests a very low but nonzero likelihood of exploitation. This vulnerability is not listed in the CISA KEV catalog. An attacker who can obtain an organization‑scoped token—such as a legitimate user or an insider—can enumerate the organization memberships of the token’s creator, bypassing the intended isolation boundaries between organizations. The attack requires only possession of a valid token; no additional exploits or vulnerabilities are needed.
OpenCVE Enrichment