Description
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and 2024.4.2 contain a patch for the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2377 | aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and 2024.4.2 contain a patch for the issue. |
Github GHSA |
GHSA-jj68-cp4v-98qf | aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services |
References
History
Tue, 15 Oct 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aimeos
Aimeos ai-admin-graphql |
|
| CPEs | cpe:2.3:a:aimeos:ai-admin-graphql:*:*:*:*:*:*:*:* cpe:2.3:a:aimeos:ai-admin-graphql:2024.04.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Aimeos
Aimeos ai-admin-graphql |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T04:19:20.752Z
Reserved: 2024-06-21T18:15:22.263Z
Link: CVE-2024-39324
Updated: 2024-07-09T15:21:08.575Z
Status : Modified
Published: 2024-07-02T21:15:11.213
Modified: 2024-11-21T09:27:27.850
Link: CVE-2024-39324
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA