PT-2024-24593 · Tolgee · Tolgee

Jan Cizmar

·

Published

2024-04-18

·

Updated

2024-04-18

·

CVE-2024-32466

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Tolgee versions prior to 3.57.2
Description Tolgee is an open-source localization platform. The issue concerns the /v2/projects/translations and /v2/projects/{projectId}/translations endpoints, where translation data was returned even when the API key was missing the translation.view scope. However, it was impossible to fetch the data when the user was missing this scope. This is only relevant for API keys generated by users permitted to translation.view.
Recommendations For versions prior to 3.57.2, update to version 3.57.2 to resolve the issue. As a temporary workaround, consider restricting access to the /v2/projects/translations and /v2/projects/{projectId}/translations endpoints for API keys without the translation.view scope.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-32466
GHSA-R95P-FQQV-FPPC

Affected Products

Tolgee