Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows an attacker who has guest account to do privilege escalation. This issue affects Apache ShardingSphere ElasticJob-UI Apache ShardingSphere ElasticJob-UI 3.x version 3.0.0 and prior versions.
VTP deterministic threat7.5of 100 · CVSS excluded
VTP analyst assessment
ElasticJob-UI guest privilege escalation
AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence79%
Public exploitation · VTP factUNKNOWN
Assessment
Apache ShardingSphere ElasticJob-UI 3.0.0 and earlier allows a guest account to escalate privileges through sensitive-information exposure. The supplied CVSS is 6.5, reflecting remote low-privilege access with high confidentiality impact. No exploitation evidence is supplied.
Why it matters
A guest user may gain access beyond intended permissions and expose sensitive information.
Any enabled or obtainable guest account could satisfy the stated prerequisite.
Evidence
1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.
Uncertainties
The supplied record does not explain the escalation mechanism, resulting privileges, or remediation version.
Only one reference is counted, with no source text, KEV entry, assertions, or first-party telemetry supplied.
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Next watchpoint
Inventory ElasticJob-UI 3.0.0 and earlier deployments and determine whether guest access is enabled.
AI baseline history (1)
BASELINE ASSESSED
ElasticJob-UI guest privilege escalationgpt-5.6-sol · high
Evidence confidence0%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
EPSS is 0.38; this is predictive context, not exploitation evidence.
02
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
02
Material change ledger
What changed
No material changes are recorded for this subject.
03
Claim provenance
Evidence and source independence
0publications detected
0underlying evidence chains
0 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.