kimai/kimai is vulnerable to Missing Authorization
27
Low Risk
The team access management API allows revoking a team's access to activities, projects, and customers while checking only the team-editing permission. Granting access requires both the team-editing right and the entity permission-management right, but the revocation endpoints omit the permission-management check. An authenticated user with team-editing rights can remove team access to entities they are not authorized to manage. The fix requires the same permission-management validation for revocation that assignment already demands.
You are affected if you are using a version that falls within the vulnerable range and you grant users team-editing rights without the corresponding entity permission-management rights.
kimai/kimai is vulnerable to Missing Authorization in versions 0.0.1 - 2.64.0.
Upgrade the kimai/kimai library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant