Information Disclosure Vulnerability in gpp-burgerportaal by Dutch Government
CVE-2025-62362
6.9MEDIUM
What is CVE-2025-62362?
The gpp-burgerportaal, a Dutch government citizen portal, exhibits an information disclosure vulnerability affecting versions prior to 2.0.3, 3.0.2, and 4.0.1. This flaw allows the exposure of employee names and email addresses in network responses, accessible through the browser's developer tools network tab. Such disclosures can jeopardize employee privacy and potentially facilitate targeted attacks or unsolicited contact with affected individuals. The issue has been rectified in the aforementioned versions, and no known workarounds are available.
Affected Version(s)
GPP-burgerportaal < 2.0.3 < 2.0.3
GPP-burgerportaal >= 3.0.0-rc.0, < 3.0.2 < 3.0.0-rc.0, 3.0.2
GPP-burgerportaal >= 4.0.0-rc.0, < 4.0.1 < 4.0.0-rc.0, 4.0.1