The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys. This endpoint requires an Editor role to access and will display API keys for all users, including Administrators.
History

Wed, 26 Nov 2025 17:45:00 +0000

Type Values Removed Values Added
Description The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys. This endpoint requires an Editor role to access and will display API keys for all users, including Administrators.
Title Opto 22 groov View Exposure of Sensitive Information Through Metadata
First Time appeared Opto 22
Opto 22 groov View Server
Opto 22 grv-epic-pr1 Firmware
Opto 22 grv-epic-pr2 Firmware
Weaknesses CWE-1230
CPEs cpe:2.3:a:opto_22:groov_view_server:*:*:windows:*:*:*:*:*
cpe:2.3:a:opto_22:grv-epic-pr1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:a:opto_22:grv-epic-pr2_firmware:*:*:*:*:*:*:*:*
Vendors & Products Opto 22
Opto 22 groov View Server
Opto 22 grv-epic-pr1 Firmware
Opto 22 grv-epic-pr2 Firmware
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L'}

cvssV4_0

{'score': 6.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-11-26T17:39:37.931Z

Reserved: 2025-11-12T19:21:15.811Z

Link: CVE-2025-13084

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.