Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
solidtime: Time entry update endpoint allows cross-organization modification of a known time-entry UUID
Vulnerability Description
solidtime is an open-source time-tracking app. In version 0.12.0, the PUT /api/v1/organizations/{organization}/time-entries/{timeEntry} API accepts a route-bound timeEntry from another organization when the caller has time-entries:update:all in the URL organization, allowing a known foreign time-entry UUID to be modified and rebound to objects in the caller's organization. This issue has been patched in version 0.12.1.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
solidtime 安全漏洞
Vulnerability Description
solidtime是solidtime开源的一个开源的时间追踪应用。 solidtime 0.12.0版本存在安全漏洞,该漏洞源于PUT /api/v1/organizations/{organization}/time-entries/{timeEntry} API接受来自其他组织的路由绑定timeEntry,可能导致修改和重新绑定已知的外部时间条目UUID。
CVSS Information
N/A
Vulnerability Type
N/A