CVE-2025-13084

The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys. This endpoint requires an Editor role to access and will display API keys for all users, including Administrators.
Configurations

No configuration.

History

26 Nov 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-26 18:15

Updated : 2025-12-01 15:39


NVD link : CVE-2025-13084

Mitre link : CVE-2025-13084

CVE.ORG link : CVE-2025-13084


JSON object : View

Products Affected

No product.

CWE
CWE-1230

Exposure of Sensitive Information Through Metadata