Kimai is a web-based multi-user time-tracking application. The permission `view_other_timesheet` performs differently for the Kimai UI and the API, thus returning unexpected data through the API. When setting the `view_other_timesheet` permission to true, on the frontend, users can only see timesheet entries for teams they are a part of. When requesting all timesheets from the API, however, all timesheet entries are returned, regardless of whether the user shares team permissions or not. This vulnerability is fixed in 2.13.0.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-03-28T13:28:36.005Z

Updated: 2024-08-02T01:10:54.793Z

Reserved: 2024-03-18T17:07:00.096Z

Link: CVE-2024-29200

cve-icon Vulnrichment

Updated: 2024-08-02T01:10:54.793Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-28T14:15:14.100

Modified: 2024-03-28T16:07:30.893

Link: CVE-2024-29200

cve-icon Redhat

No data.