CVE-2024-39322

aimeos/ai-admin-jsonadm is the Aimeos e-commerce JSON API for administrative tasks. In versions prior to 2020.10.13, 2021.10.6, 2022.10.3, 2023.10.4, and 2024.4.2, improper access control allows editors to remove admin group and locale configuration in the Aimeos backend. Versions 2020.10.13, 2021.10.6, 2022.10.3, 2023.10.4, and 2024.4.2 contain a fix for the issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:aimeos_project:ai-controller-frontend:2024.04.1:*:*:*:*:*:*:*
cpe:2.3:a:aimeos_project:ai-controller-frontend:*:*:*:*:*:*:*:*
cpe:2.3:a:aimeos_project:ai-controller-frontend:*:*:*:*:*:*:*:*
cpe:2.3:a:aimeos_project:ai-controller-frontend:*:*:*:*:*:*:*:*
cpe:2.3:a:aimeos_project:ai-controller-frontend:*:*:*:*:*:*:*:*

History

15 Oct 2024, 20:47

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References () https://github.com/aimeos/ai-admin-jsonadm/commit/4c966e02bd52589c3c9382777cfe170eddf17b00 - () https://github.com/aimeos/ai-admin-jsonadm/commit/4c966e02bd52589c3c9382777cfe170eddf17b00 - Patch
References () https://github.com/aimeos/ai-admin-jsonadm/commit/16d013d0e28cecd19781f434d83fabebcc78cdc2 - () https://github.com/aimeos/ai-admin-jsonadm/commit/16d013d0e28cecd19781f434d83fabebcc78cdc2 - Patch
References () https://github.com/aimeos/ai-admin-jsonadm/security/advisories/GHSA-8fj2-587w-5whr - () https://github.com/aimeos/ai-admin-jsonadm/security/advisories/GHSA-8fj2-587w-5whr - Third Party Advisory
References () https://github.com/aimeos/ai-admin-jsonadm/commit/7d1c05e8368b0a6419820fe402deac9960500026 - () https://github.com/aimeos/ai-admin-jsonadm/commit/7d1c05e8368b0a6419820fe402deac9960500026 - Patch
References () https://github.com/aimeos/ai-admin-jsonadm/commit/02a063fbd616d4e0a5aaf89f1642a856aa5ac5a5 - () https://github.com/aimeos/ai-admin-jsonadm/commit/02a063fbd616d4e0a5aaf89f1642a856aa5ac5a5 - Patch
References () https://github.com/aimeos/ai-admin-jsonadm/commit/640954243ce85c2c303a00dd6481ed39b3d218fb - () https://github.com/aimeos/ai-admin-jsonadm/commit/640954243ce85c2c303a00dd6481ed39b3d218fb - Patch
First Time Aimeos Project ai-controller-frontend
Aimeos Project
CPE cpe:2.3:a:aimeos_project:ai-controller-frontend:*:*:*:*:*:*:*:*
cpe:2.3:a:aimeos_project:ai-controller-frontend:2024.04.1:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo

02 Jul 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-02 21:15

Updated : 2024-10-15 20:47


NVD link : CVE-2024-39322

Mitre link : CVE-2024-39322


JSON object : View

Products Affected

aimeos_project

  • ai-controller-frontend