aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
High severity
GitHub Reviewed
Published
Jul 2, 2024
in
aimeos/ai-admin-graphql
•
Updated Jul 5, 2024
Package
Affected versions
>= 2022.04.1, < 2022.10.10
>= 2023.04.1, < 2023.10.6
>= 2024.04.1, < 2024.04.6
Patched versions
2022.10.10
2023.10.6
2024.04.6
Description
Published by the National Vulnerability Database
Jul 2, 2024
Published to the GitHub Advisory Database
Jul 2, 2024
Reviewed
Jul 2, 2024
Last updated
Jul 5, 2024
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue.
References