OSV 1.4.0 · unreviewed · 修改于 2026-09-01 05:31
发布时间
2026-09-01 05:31
GitHub 审查时间
—
NVD 发布时间
2026-08-26 13:18
源文件
advisories/unreviewed/2026/08/GHSA-fp3h-853f-fcf4/GHSA-fp3h-853f-fcf4.json
Kimai before 2.64.0 contains a missing authorization vulnerability in the ProjectViewController export route (report_project_view_export). The authorization guards are attached to the sibling __invoke method rather than at the class level, so the export route inherits no authorization checks. Any authenticated user, including a plain ROLE_USER without the project_reporting permission, can download the project overview export - which returns the same dataset as the protected report - disclosing customer names, project names, currency, budget type, and aggregate totals across all customers. Actual financial figures remain protected in the export template.
该公告没有提供结构化的受影响软件包信息。