As a manager, you should not be able to modify a series of settings. In the UI this is indeed hidden as a convenience for the role since most managers would not be savvy enough to modify these settings. They can use their token to still modify those settings though through a standard HTTP request

While this is not a critical vulnerability, it does indeed need to be patched to enforce the expected permission level.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published:

Updated: 2024-08-21T15:10:35.855Z

Reserved: 2024-01-11T19:54:59.182Z

Link: CVE-2024-0439

cve-icon Vulnrichment

Updated: 2024-08-01T18:04:49.767Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-02-26T16:27:50.490

Modified: 2024-11-21T08:46:35.647

Link: CVE-2024-0439

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.