kimai/kimai is vulnerable to Incorrect Authorization
27
Low Risk
The REST API timesheet collection endpoint does not enforce activity-team access controls when listing timesheets. The permission criteria applied to the collection query validates only project and customer team permissions. A user with permission to view other timesheets can list entries tied to activities restricted to teams they do not belong to, even though the single-entity endpoint correctly denies access. The fix extends the query filtering to include activity-team restrictions.
You are affected if you are using a version that falls within the vulnerable range and you grant users permission to view other users' timesheets while relying on activity-team restrictions.
kimai/kimai is vulnerable to Incorrect Authorization in versions 0.0.1 - 2.64.0.
Upgrade the kimai/kimai library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant