MEDIUM 5.8 Go

Duplicate Advisory: Tag labels from password-protected documents are returned to readers who have not entered the password

GHSA-f68g-4xv8-2g75

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-mp7r-57w4-5qm3. This link is maintained to preserve external references.

Original Description

SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/tag/getTag endpoint that returns tag labels and occurrence counts from password-protected documents to unauthenticated readers. Attackers can enumerate tag vocabulary and internal terminology from password-protected documents by calling the tag endpoint without providing the document's publish password.

Ready to move

Start Securing

Free, no credit card | First findings in minutes