{"id":"CVE-2024-22889","aliases":["GHSA-xg5p-8wg5-rhxm","PYSEC-2026-1798"],"title":"Phone information disclosure vulnerability","summary":"Phone information disclosure vulnerability","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","vendor":"plone","product":"plone","ecosystem":"pip","affected":["plone <= 6.0.9"],"published":"2024-03-06","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-xg5p-8wg5-rhxm","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-22889"},{"url":"https://github.com/plone/Plone"},{"url":"https://github.com/shenhav12/CVE-2024-22889-Plone-v6.0.9"}],"tags":["osv","pip","exploit-available"],"epss":0.00697,"epssPercentile":0.51201,"ingestedAt":"2026-07-08T18:25:54.181Z","exploits":{"github":1,"githubRepos":["https://github.com/shenhav12/CVE-2024-22889-Plone-v6.0.9"],"checkedAt":"2026-09-21T15:26:20.541Z"},"exploitAvailable":true,"slug":"CVE-2024-22889","body":"## Overview\n\nDue to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request.\n\n## Affected packages\n\n- `plone <= 6.0.9`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":30.3,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":4699,"id":"CVE-2024-22889","ts":1788887200105,"field":"exploit_available","old":"false","new":"true"},{"seq":3582,"id":"CVE-2024-22889","ts":1788886316585,"field":"exploit_available","old":"true","new":"false"},{"seq":2436,"id":"CVE-2024-22889","ts":1788882985310,"field":"exploit_available","old":"false","new":"true"},{"seq":1465,"id":"CVE-2024-22889","ts":1788882398613,"field":"exploit_available","old":"true","new":"false"},{"seq":579,"id":"CVE-2024-22889","ts":1788881835262,"field":"exploit_available","old":"false","new":"true"}]}