Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' timesheet records without being teamlead of the target
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 6.3epss 0.4%
probabilidade de exploração
0.4%top 69% das CVEs
exploração observada
nãonenhuma fonte reporta
Kimai is an open-source time tracking application. Prior to 2.57.0, the GET /api/timesheets list endpoint accepts user and users[] target identifiers from a caller with view_other_timesheet but does not apply access_user or verify that a ROLE_TEAMLEAD requester leads a team containing each target user. TimesheetController::cgetAction() adds the resolved users directly to the query while project and customer filtering still permits records on unscoped projects or projects sharing ordinary team membership, allowing a teamlead to retrieve another user's descriptions, timing data, tags, rate, and internalRate even though GET /api/timesheets/{id} would deny access through TimesheetVoter. This issue is fixed in version 2.57.0.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Produtos afetados
kimai · kimaiReferências
https://github.com/kimai/kimai/commit/976d38e8a4485a1c923ee7b5841849e91a06e849https://github.com/kimai/kimai/pull/5929https://github.com/kimai/kimai/releases/tag/2.57.0https://github.com/kimai/kimai/security/advisories/GHSA-4m8q-55qv-9pwphttps://www.kimai.org/en/security/ghsa-4m8q-55qv-9pwp