Skip to content

BuddyPress private data exposure via REST API

Critical
ehti published GHSA-3j78-7m59-r7gv Feb 24, 2020

Package

No package listed

Affected versions

5.0.0 - 5.1.1

Patched versions

5.1.2

Description

Impact

Requests to a certain REST API endpoint can result in private user data getting exposed. Authentication is not needed.

Patches

This has been patched in version 5.1.2. It's strongly encouraged to update to the latest version.

References

https://buddypress.org/2020/01/buddypress-5-1-2/

For more information

Any security reports in BuddPyress can be submitted via HackerOne

Severity

Critical

CVE ID

CVE-2020-5244

Weaknesses

No CWEs