Home
MEDIUM: 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N < 2.4.28
affected
Description
IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 return sensitive data to the user which are not required for the client’s operation. Version 2.4.28 contains a patch.
Problem types
CWE-201: Insertion of Sensitive Information Into Sent Data
Product status
References
www.openwall.com/lists/oss-security/2026/05/19/9
github.com/...is-web/security/advisories/GHSA-g588-5gmf-p5cx