kimai/kimai is vulnerable to Improper Authorization
31
Low Risk
The team update API endpoint accepts a members parameter and deletes all existing team member and teamlead rows before validating the submitted replacement list. When a malformed members payload is sent, the request returns a validation error but the membership rows have already been removed, disrupting team-scoped access control. The fix validates the replacement member list before any changes are made so invalid data leaves the existing membership unchanged.
You are affected if you are using a version that falls within the vulnerable range and your deployment allows non-admin users to edit teams.
kimai/kimai is vulnerable to Improper Authorization in versions 0.0.1 - 2.62.0.
Upgrade the kimai/kimai library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant