← back
CVE-2025-13084mediumCWE-1230

Opto 22 groov View Exposure of Sensitive Information Through Metadata

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.1epss 0.3%
exploitation probability
0.3%top 82% of all CVEs
observed exploitation
nono source reports it
In short

The groov View API exposes users' API keys through a public endpoint that requires only Editor-level access. An attacker with Editor permissions can retrieve secret API keys for all users, including administrators, compromising account security.

Technical detail

The /users endpoint in groov View API returns sensitive metadata including plaintext or insufficiently protected API keys for all users regardless of role hierarchy. An authenticated attacker with Editor privileges can enumerate and extract API credentials for administrative accounts, leading to unauthorized access and privilege escalation.

Summary generated and translated by AI from the official description.
The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys. This endpoint requires an Editor role to access and will display API keys for all users, including Administrators.
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N