CVE-2024-32466

CVSS V2 None CVSS V3 None
Description
Tolgee is an open-source localization platform. For the `/v2/projects/translations` and `/v2/projects/{projectId}/translations` endpoints, translation data was returned even when API key was missing `translation.view` scope. However, it was impossible to fetch the data when user was missing this scope. So this is only relevant for API keys generated by users permitted to `translation.view`. This vulnerability is fixed in v3.57.2
Overview
  • CVE ID
  • CVE-2024-32466
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-04-18T15:02:43.803Z
  • Last Modified Date
  • 2024-04-18T15:02:43.803Z
History
Created Old Value New Value Data Type Notes
2024-06-26 08:25:02 Added to TrackCVE