Impact
This vulnerability originates in the official Kimai Docker image for versions before 2.58.0, which hard‑codes the APP_SECRET to "change_this_to_something_unique" in the Dockerfile. The Docker image's entrypoint does not replace or reject this default value before Symfony uses it as kernel.secret. Because the kernel.secret is used as the key for HMAC‑protected authentication artifacts, an attacker who can reach an unpatched deployment, knows a victim's username, and can correctly guess the associated account ID can forge KIMAI_REMEMBER cookies or login links if two‑factor authentication is disabled. The attacker can therefore authenticate as the target without the password, enabling full account takeover. The entrypoint has been updated in Kimai 2.58.0 to generate and persist a random secret when no operator‑provided value is present, fixing the issue. The weakness is identified as CWE‑1188.
Affected Systems
The affected environment is the official Kimai Docker image provided by the kimai:kimai project. Versions of the image prior to Kimai 2.58.0 contain the default, hard‑coded APP_SECRET value. Updating to Kimai 2.58.0 or later replaces the entrypoint logic with generation of a random secret when one is not supplied by a secure operator, thereby removing the vulnerability.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity. The EPSS score of 2% indicates a moderate likelihood that the vulnerability will be exploited. It is not KEV catalog. An attacker with unauthenticated network access can, with knowledge of a target username and account ID and the absence of second‑factor authentication, forge authentication artifacts through HMAC manipulation. Forged artifacts allow the attacker to impersonate the target user with full privileges without the original password.
OpenCVE Enrichment
Github GHSA