VulnerabilityAnalyzed
CVE-2024-32470
When API key created by admin user is used it bypasses the permission check at all.
MEDIUM 6.5EPSS 0.56%
Does this matter?
Lower severity and a low EPSS score (0.56%). Track it; it rarely justifies an emergency change on its own.
Description
Tolgee is an open-source localization platform. When API key created by admin user is used it bypasses the permission check at all. This error was introduced in v3.57.2 and immediately fixed in v3.57.4.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 0.56% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- tolgee/tolgee
- Source
- security-advisories@github.com
References
- https://github.com/tolgee/tolgee-platform/commit/a0d861028d931f8a54387770eaf3a75031b81234Patch
- https://github.com/tolgee/tolgee-platform/security/advisories/GHSA-pm57-hcm8-38gwVendor Advisory
- https://github.com/tolgee/tolgee-platform/security/advisories/GHSA-r95p-fqqv-fppcNot Applicable
- https://github.com/tolgee/tolgee-platform/commit/a0d861028d931f8a54387770eaf3a75031b81234Patch
- https://github.com/tolgee/tolgee-platform/security/advisories/GHSA-pm57-hcm8-38gwVendor Advisory
- https://github.com/tolgee/tolgee-platform/security/advisories/GHSA-r95p-fqqv-fppcNot Applicable
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.