Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 26 Mar 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Solidtime
Solidtime solidtime |
|
| CPEs | cpe:2.3:a:solidtime:solidtime:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Solidtime
Solidtime solidtime |
Wed, 25 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Solidtime-io
Solidtime-io solidtime |
|
| Vendors & Products |
Solidtime-io
Solidtime-io solidtime |
Tue, 24 Mar 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | solidtime is an open-source time-tracking app. Prior to version 0.11.6, the project detail endpoint GET /api/v1/organizations/{org}/projects/{project} allows any authenticated Employee to access any project in the organization by UUID, including private projects they are not a member of. The index() endpoint correctly applies the visibleByEmployee() scope, but show() does not. This issue has been patched in version 0.11.6. | |
| Title | solidtime vulnerable to IDOR in private projects | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-25T13:21:58.960Z
Reserved: 2026-03-18T22:15:11.813Z
Link: CVE-2026-33345
Updated: 2026-03-25T13:21:40.910Z
Status : Analyzed
Published: 2026-03-24T20:16:29.073
Modified: 2026-03-26T13:21:21.500
Link: CVE-2026-33345
No data.
OpenCVE Enrichment
Updated: 2026-03-25T20:57:39Z