CVE-2025-62362

Source
https://cve.org/CVERecord?id=CVE-2025-62362
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-62362.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-62362
Aliases
  • GHSA-pgg6-2865-2788
Published
2025-10-13T21:33:35.199Z
Modified
2026-04-10T05:33:57.124573Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N CVSS Calculator
Summary
Name and e-mail of employee that has done a publication is discoverable in gpp-burgerportaal
Details

gpp-burgerportaal is a Dutch government citizen portal application. In versions before 2.0.3, 3.0.2, and 4.0.1, the name and email address of employees who publish content are exposed in network responses and can be discovered by viewing the browser's developer tools network tab. This information disclosure may violate employee privacy expectations and could be used for targeted attacks or unwanted contact. This issue has been patched in versions 2.0.3, 3.0.2, and 4.0.1. No known workarounds exist.

Database specific
{
    "cwe_ids": [
        "CWE-359"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/62xxx/CVE-2025-62362.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/gpp-woo/gpp-burgerportaal

Affected ranges

Type
GIT
Repo
https://github.com/gpp-woo/gpp-burgerportaal
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.0.3"
        }
    ]
}
Type
GIT
Repo
https://github.com/gpp-woo/gpp-burgerportaal
Events
Database specific
{
    "versions": [
        {
            "introduced": "3.0.0-rc.0"
        },
        {
            "fixed": "3.0.2"
        }
    ]
}
Type
GIT
Repo
https://github.com/gpp-woo/gpp-burgerportaal
Events
Database specific
{
    "versions": [
        {
            "introduced": "4.0.0-rc.0"
        },
        {
            "fixed": "4.0.1"
        }
    ]
}

Affected versions

1.*
1.0.0-rc.0
2.*
2.0.0
2.0.0-rc.0
2.0.0-rc.1
2.0.1
2.0.2
3.*
3.0.0
3.0.0-rc.0
3.0.0-rc.1
3.0.1
4.*
4.0.0
4.0.0-rc.0
4.0.0-rc.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-62362.json"