{"id":"CVE-2022-24111","details":"In Mahara 21.04 before 21.04.3 and 21.10 before 21.10.1, portfolios created in groups that have not been shared with non-group members and portfolios created on the site and institution levels can be viewed without requiring a login if the URL to these portfolios is known.","modified":"2025-11-14T13:02:22.124149Z","published":"2022-02-10T16:15:07.970Z","references":[{"type":"ADVISORY","url":"https://bugs.launchpad.net/mahara/+bug/1959146"},{"type":"ADVISORY","url":"https://mahara.org/interaction/forum/topic.php?id=8996"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/maharaproject/mahara","events":[{"introduced":"359597b32c7afe52339422a91f14256e17b33dfc"},{"fixed":"52109b30a7a9fa34ccd79bffe1ec42df3e9d3cc7"}]}],"versions":["21.04.0_RELEASE","21.04.1_RELEASE","21.04.2_RELEASE"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-24111.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}