aimeos/ai-admin-jsonadm is the Aimeos e-commerce JSON API for administrative tasks. In versions prior to 2020.10.13, 2021.10.6, 2022.10.3, 2023.10.4, and 2024.4.2, improper access control allows editors to remove admin group and locale configuration in the Aimeos backend. Versions 2020.10.13, 2021.10.6, 2022.10.3, 2023.10.4, and 2024.4.2 contain a fix for the issue.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2296 | aimeos/ai-admin-jsonadm is the Aimeos e-commerce JSON API for administrative tasks. In versions prior to 2020.10.13, 2021.10.6, 2022.10.3, 2023.10.4, and 2024.4.2, improper access control allows editors to remove admin group and locale configuration in the Aimeos backend. Versions 2020.10.13, 2021.10.6, 2022.10.3, 2023.10.4, and 2024.4.2 contain a fix for the issue. |
Github GHSA |
GHSA-8fj2-587w-5whr | aimeos/ai-admin-jsonadm improper access control vulnerability allows editors to remove required records |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 15 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aimeos Project
Aimeos Project ai-controller-frontend |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:aimeos_project:ai-controller-frontend:*:*:*:*:*:*:*:* cpe:2.3:a:aimeos_project:ai-controller-frontend:2024.04.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Aimeos Project
Aimeos Project ai-controller-frontend |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T04:19:20.705Z
Reserved: 2024-06-21T18:15:22.263Z
Link: CVE-2024-39322
Updated: 2024-07-03T20:29:17.856Z
Status : Modified
Published: 2024-07-02T21:15:10.997
Modified: 2024-11-21T09:27:27.537
Link: CVE-2024-39322
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA