PT-2024-24593 · Tolgee · Tolgee
Jan Cizmar
·
Published
2024-04-18
·
Updated
2024-04-18
·
CVE-2024-32466
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Tolgee versions prior to 3.57.2
Description
Tolgee is an open-source localization platform. The issue concerns the
/v2/projects/translations and /v2/projects/{projectId}/translations endpoints, where translation data was returned even when the API key was missing the translation.view scope. However, it was impossible to fetch the data when the user was missing this scope. This is only relevant for API keys generated by users permitted to translation.view.Recommendations
For versions prior to 3.57.2, update to version 3.57.2 to resolve the issue. As a temporary workaround, consider restricting access to the
/v2/projects/translations and /v2/projects/{projectId}/translations endpoints for API keys without the translation.view scope.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tolgee