Opto 22 groov View Exposure of Sensitive Information Through Metadata
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.1epss 0.3%
exploitation probability
0.3%top 82% of all CVEs
observed exploitation
nono source reports it
In short
The groov View API exposes users' API keys through a public endpoint that requires only Editor-level access. An attacker with Editor permissions can retrieve secret API keys for all users, including administrators, compromising account security.
Technical detail
The /users endpoint in groov View API returns sensitive metadata including plaintext or insufficiently protected API keys for all users regardless of role hierarchy. An authenticated attacker with Editor privileges can enumerate and extract API credentials for administrative accounts, leading to unauthorized access and privilege escalation.
Summary generated and translated by AI from the official description.
The users endpoint in the groov View API returns a list of all users and
associated metadata including their API keys. This endpoint requires an
Editor role to access and will display API keys for all users,
including Administrators.
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N