Impact
A flaw in grimmory’s Settings API endpoint, specifically the AppSettingController.getAppSettings function, allows an attacker to bypass normal authorization checks. This incorrect authorization can grant unauthorized users access to application settings data or functionality that should be protected, potentially enabling further exploitation of the system.
Affected Systems
The vulnerability affects grimmory-tools’ grimmory component versions up to 3.3.3 and 3.4.1. It is present in the backend module located in backend/src/main/java/org/booklore/controller/AppSettingController.java and impacts the GET /api/v1/settings interface.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog, but the exploit has been publicly disclosed and can be launched remotely. Attackers can use the exposed endpoint to read or modify configuration settings, potentially escalating privileges or compromising the application’s security posture.
OpenCVE Enrichment