Home
HIGH: 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:LMEDIUM: 6.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:NDefault status
unaffected
R1.0a (custom)
affected
Default status
unaffected
Any version
affected
Default status
unaffected
Any version
affected
Description
The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys. This endpoint requires an Editor role to access and will display API keys for all users, including Administrators.
Problem types
Product status
R1.0a (custom)
Any version
Any version
Credits
Nik Tsytsarkin, Ismail Aydemir, and Ryan Hall of Meta reported this vulnerability to CISA.
References
www.opto22.com/support/resources-tools/knowledgebase/kb91325
www.cisa.gov/news-events/ics-advisories/icsa-25-329-04
github.com/...p/csaf_files/OT/white/2025/icsa-25-329-04.json