A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data.
References
Configurations
No configuration.
History
23 Oct 2025, 12:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-23 12:15
Updated : 2025-10-23 12:15
NVD link : CVE-2025-62395
Mitre link : CVE-2025-62395
CVE.ORG link : CVE-2025-62395
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control
