Multiple Security Misconfigurations and Customer Enumeration Exposure in Convercent Whistleblowing Platform (EQS Group)
EQS Group的SaaS平台存在安全漏洞,最初被分配CVE编号后又被撤销。由于平台由供应商独家托管且用户无法自行修复,CVE认为不适用。尽管漏洞真实存在并已修复,但这一决定凸显了SaaS平台漏洞难以公开追踪的问题。 2026-1-6 07:0:51 Author: seclists.org(查看原文) 阅读量:5 收藏

fulldisclosure logo

Full Disclosure mailing list archives


From: Yuffie Kisaragi via Fulldisclosure <fulldisclosure () seclists org>
Date: Sun, 04 Jan 2026 22:01:57 +0000

UPDATE:




Following the publication of these vulnerabilities and the subsequent CVE
assignments, the CVE identifiers have now been revoked.




The vendor (EQS Group) contacted the CVE Program (via a CNA) and disputed the
records, stating that the affected product is an exclusively hosted SaaS
platform with no customer-managed deployment or versioning. Based on this
argument, the CVE Program concluded that CVE assignment is “not a suitable
solution for vulnerability identification” in this case, as customers do not
take direct action to apply fixes.




In other words, because the service is centrally hosted and patched at the
provider’s discretion, the vulnerabilities are no longer considered eligible for
CVE tracking, despite being real, independently discovered, responsibly
disclosed, and acknowledged by the vendor.

The vendor has stated that fixes are being implemented and that private customer
notifications will be issued internally.




While remediation is of course welcome, this outcome highlights a broader issue:
vulnerabilities in SaaS platforms can effectively disappear from public
vulnerability tracking, simply because the deployment model removes user agency,
a model that arguably incentivizes security through obscurity, rather than
transparency.




The technical findings remain valid.




This update is shared purely for accuracy and record-keeping.

On Sun, Jan 4, 2026 at 4:40 PM <yuffie.kisaragi () atomicmail io
[yuffie.kisaragi () atomicmail io]> wrote:
UPDATE:


The reported vulnerabilities have now been assigned CVE identifiers:
CVE-2025-34411: https://www.cve.org/cverecord?id=CVE-2025-34411
[https://www.cve.org/cverecord?id=CVE-2025-34411]
CVE-2025-34412: https://www.cve.org/cverecord?id=CVE-2025-34412
[https://www.cve.org/cverecord?id=CVE-2025-34412]
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/

Current thread:

  • Multiple Security Misconfigurations and Customer Enumeration Exposure in Convercent Whistleblowing Platform (EQS Group) Yuffie Kisaragi via Fulldisclosure (Jan 05)

文章来源: https://seclists.org/fulldisclosure/2026/Jan/4
如有侵权请联系:admin#unsafe.sh