CVE 5.3 MEDIUM

GoJobs: Insecure Direct Object Reference (IDOR) in Job Retrieval Endpoint_CVE-2026-44341

5.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Description

GoJobs is a REST API for a Job Board platform. The application exposes a job retrieval endpoint that allows unauthenticated users to access job details by directly manipulating object identifiers. The endpoint lacks proper authentication and authorization checks, resulting in unauthorized access to job data.

Basic Information

ID CVE-2026-44341
Source GitHub_M
Published May 12, 2026 at 22:39

Affected Product

Vendor karnop
Product gojobs
Version <= 2cc74a78dcf101c089ea209f2aaefef0674f6b55
Affected Versions karnop gojobs <= 2cc74a78dcf101c089ea209f2aaefef0674f6b55

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.