6.5
CVE-2024-32470
- EPSS 0.56%
- Veröffentlicht 18.04.2024 15:15:30
- Zuletzt bearbeitet 11.09.2025 21:29:07
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Tolgee' API keys created by server admin users bypass the permission check
Tolgee is an open-source localization platform. When API key created by admin user is used it bypasses the permission check at all. This error was introduced in v3.57.2 and immediately fixed in v3.57.4.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.56% | 0.419 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 6.5 | 1.2 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://github.com/tolgee/tolgee-platform/security/advisories/GHSA-r95p-fqqv-fppc
https://github.com/tolgee/tolgee-platform/commit/a0d861028d931f8a54387770eaf3a75031b81234
https://github.com/tolgee/tolgee-platform/security/advisories/GHSA-pm57-hcm8-38gw