kimai/kimai is vulnerable to Privilege Escalation
54
Medium Risk
The team-assignment API endpoints for customers, projects, and activities reuse an existing team when a team with the same name already exists. When reusing that team, Kimai adds the current user as a team lead without checking that the user is authorized to manage the reused team. An authenticated user with project permission-management rights can become team lead of an existing team by matching its name. The fix creates a new team through the protected form routes instead of silently reusing and joining an existing one.
You are affected if you are using a version that falls within the vulnerable range and you grant users project permission-management rights.
kimai/kimai is vulnerable to Privilege Escalation in versions 0.0.1 - 2.64.0.
Upgrade the kimai/kimai library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant