GROWI に複数の脆弱性
予習
この記事のキーワード — タップで意味×3
脆弱性
ぜいじゃくせい
vulnerability; weakness; fragility
×3
取得
しゅとく
acquisition; obtaining; gaining possession; purchase
×2
攻撃者
こうげきしゃ
aggressor; assailant; invader
×2
当該
とうがい
appropriate (e.g. authorities); concerned; relevant; said; aforementioned; competent; applicable; respective
×2
株式会社
かぶしきがいしゃ
stock company; corporation; kabushiki kaisha; KK
独立行政法人情報処理推進機構(IPA)および一般社団法人JPCERT コーディネーションセンター(JPCERT/CC)は8月28日、GROWIにおける複数の脆弱性について「Japan Vulnerability Notes(JVN)」で発表した。河本将士氏、株式会社日本総合研究所の大竹文絃氏が報告を行っている。影響を受けるシステムは以下の通り。
GROWI v8.0.0およびそれ以前のバージョン
株式会社GROWIが提供するGROWIには、下記の影響を受ける可能性がある複数の脆弱性が存在する。
・ブックマークフォルダ関連APIにおけるユーザ識別情報の操作による権限チェック回避(CVE-2026-53620) →当該製品にログイン可能な攻撃者によって、他のユーザのブックマーク情報が取得、改ざん、削除される
・ブックマーク一覧取得APIにおける認可処理の不備(CVE-2026-68951) →当該製品にアクセス可能な攻撃者によって、他のユーザのブックマーク情報が取得される
JVNでは、開発者が提供する情報をもとに最新版へアップデートするよう呼びかけている。なお本脆弱性は、GROWI v8.0.1で修正されている。
GROWI v8.0.0およびそれ以前のバージョン
株式会社GROWIが提供するGROWIには、下記の影響を受ける可能性がある複数の脆弱性が存在する。
・ブックマークフォルダ関連APIにおけるユーザ識別情報の操作による権限チェック回避(CVE-2026-53620) →当該製品にログイン可能な攻撃者によって、他のユーザのブックマーク情報が取得、改ざん、削除される
・ブックマーク一覧取得APIにおける認可処理の不備(CVE-2026-68951) →当該製品にアクセス可能な攻撃者によって、他のユーザのブックマーク情報が取得される
JVNでは、開発者が提供する情報をもとに最新版へアップデートするよう呼びかけている。なお本脆弱性は、GROWI v8.0.1で修正されている。
この記事の単語 (46)
×4
情報
じょうほう
1. information; news; intelligence; advices 2. information; data contained in characters, signals, code, etc.
×3
脆弱性
ぜいじゃくせい
vulnerability; weakness; fragility
×3
取得
しゅとく
acquisition; obtaining; gaining possession; purchase
×2
及び
および
and; as well as
×2
複数
ふくすう
plural; multiple; several
×2
株式会社
かぶしきがいしゃ
stock company; corporation; kabushiki kaisha; KK
×2
影響
えいきょう
1. influence; effect 2. to influence; to affect; to have an influence on; to impact; to have an effect on
×2
提供
ていきょう
1. offer; tender; providing; supplying; making available; donating (blood, organs, etc.) 2. sponsoring (a TV program)
×2
当該
とうがい
appropriate (e.g. authorities); concerned; relevant; said; aforementioned; competent; applicable; respective
×2
製品
せいひん
manufactured goods; finished goods; product
×2
可能
かのう
possible; potential; practicable; feasible
×2
攻撃者
こうげきしゃ
aggressor; assailant; invader
×2
他
た
other (esp. people and abstract matters)
×1
独立行政法人
どくりつぎょうせいほうじん
independent administrative corporation (institution, agency)
×1
情報処理推進機構
じょうほうしょりすいしんきこう
Information-technology Promotion Agency (organization)
×1
一般社団法人
いっぱんしゃだんほうじん
general incorporated association
×1
発表
はっぴょう
announcement; publication; presenting; statement; communique; making known; breaking (news story); expressing (one's opinion); releasing; unveiling
×1
河本
かわもと
Kawamoto (place; surname)
×1
将士
しょうし
officers and men
×1
日本
にほん
Japan
×1
総合研究所
そうごうけんきゅうしょ
institute for general research; multidiscipline laboratory
×1
大竹
おうたけ
Outake (surname)
×1
絃
げん
1. string (of a shamisen, etc.) 2. stringed instrument
×1
報告
ほうこく
report; information
×1
通り
とおり
1. avenue; street; way; road 2. coming and going; street traffic
×1
以前
いぜん
ago; since; before; previous
×1
下記
かき
the following
×1
可能性
かのうせい
potentiality; likelihood; possibility; availability
×1
存在
そんざい
existence; being
×1
関連
かんれん
relation; connection; relevance
×1
識別
しきべつ
discrimination; discernment; identification
×1
操作
そうさ
1. operation; management; handling 2. manipulating (to one's benefit); manipulation; influencing
×1
権限
けんげん
power; authority; jurisdiction
×1
回避
かいひ
evasion; avoidance
×1
改竄
かいざん
alteration; falsification; faking
×1
削除
さくじょ
deletion; elimination; erasure; striking out
×1
一覧
いちらん
1. look; glance; sight; inspection 2. summary; list; table; catalog; catalogue
×1
認可
にんか
approval; license; licence; permission
×1
処理
しょり
processing; dealing with; treatment; disposition; disposal
×1
不備
ふび
1. defect; deficiency; imperfection; inadequacy; lack 2. Yours in haste
×1
開発者
かいはつしゃ
developer
×1
もと
1. origin; source 2. base; basis; foundation; root
×1
最新版
さいしんばん
latest version; latest edition
×1
呼び掛ける
よびかける
1. to call out to; to hail; to address 2. to appeal
×1
猶
なお
1. still; yet 2. more; still more; greater; further
×1
修正
しゅうせい
amendment; correction; revision; modification; alteration; retouching; update; fix