Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gq43-vcrh-6jw8

Опубликовано: 13 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 5.8

Описание

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/block/getRefIDs endpoint that fails to check password-protected document tiers. Unauthenticated readers can discover that password-protected documents reference specific blocks and obtain block identifiers without entering the document password.

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/block/getRefIDs endpoint that fails to check password-protected document tiers. Unauthenticated readers can discover that password-protected documents reference specific blocks and obtain block identifiers without entering the document password.

EPSS

Процентиль: 9%
0.00194
Низкий

6.9 Medium

CVSS4

5.8 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 5.8
nvd
27 дней назад

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/block/getRefIDs endpoint that fails to check password-protected document tiers. Unauthenticated readers can discover that password-protected documents reference specific blocks and obtain block identifiers without entering the document password.

EPSS

Процентиль: 9%
0.00194
Низкий

6.9 Medium

CVSS4

5.8 Medium

CVSS3

Дефекты

CWE-639