Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gv2h-crgm-gfwc

Опубликовано: 15 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by unauthenticated public report and experiment endpoints. Attackers with knowledge of a publicly shared report or experiment identifier can read internal data warehouse query text, schema, table names, filter values and datasource identifiers.

GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by unauthenticated public report and experiment endpoints. Attackers with knowledge of a publicly shared report or experiment identifier can read internal data warehouse query text, schema, table names, filter values and datasource identifiers.

EPSS

Процентиль: 16%
0.00244
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-201

Связанные уязвимости

CVSS3: 5.3
nvd
5 дней назад

GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by unauthenticated public report and experiment endpoints. Attackers with knowledge of a publicly shared report or experiment identifier can read internal data warehouse query text, schema, table names, filter values and datasource identifiers.

EPSS

Процентиль: 16%
0.00244
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-201