kimai/kimai is vulnerable to Incorrect Authorization
54
Medium Risk
The team access API endpoints for customers, projects, and activities check only view permission on the target entity instead of the permission-management right. An authenticated user with team-editing rights and read-only access to an entity can grant their own team access to that entity. This lets a user expand team access to resources they are not authorized to manage. The fix replaces the view checks with proper permission validation on every entity type.
You are affected if you are using a version that falls within the vulnerable range and you grant users team-editing rights together with read-only access to customers, projects, or activities.
kimai/kimai is vulnerable to Incorrect Authorization in versions 0.0.1 - 2.62.0.
Upgrade the kimai/kimai library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant