CVE-2024-29200

CVSS V2 None CVSS V3 None
Description
Kimai is a web-based multi-user time-tracking application. The permission `view_other_timesheet` performs differently for the Kimai UI and the API, thus returning unexpected data through the API. When setting the `view_other_timesheet` permission to true, on the frontend, users can only see timesheet entries for teams they are a part of. When requesting all timesheets from the API, however, all timesheet entries are returned, regardless of whether the user shares team permissions or not. This vulnerability is fixed in 2.13.0.
Overview
  • CVE ID
  • CVE-2024-29200
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-03-28T13:28:36.005Z
  • Last Modified Date
  • 2024-03-28T13:28:36.005Z
References
Reference URL Reference Tags
https://github.com/kimai/kimai/security/advisories/GHSA-cj3c-5xpm-cx94 x_refsource_CONFIRM
History
Created Old Value New Value Data Type Notes
2024-06-26 02:37:03 Added to TrackCVE