CVE-2022-24841: Improper Authorization in github.com/fleetdm/fleet

Published Apr 18, 2022
·
Updated

fleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams feature are affected by this authorization bypass issue. Fleet instances without teams, or with teams but without restricted team accounts are not affected. In affected versions a team admin can erroneously add themselves as admin, maintainer or observer on other teams. Users are advised to upgrade to version 4.13. There are no known workarounds for this issue.

Affected Software

1 affected component
fleetdm fleet<4.13

Event History

Apr 18, 2022
CVE Published
via MITRE·09:20 PM
Data Sourced
via MITRE·09:20 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2022-24841?

CVE-2022-24841 has been classified as a medium severity vulnerability due to its potential for unauthorized access.

2

How do I fix CVE-2022-24841?

To fix CVE-2022-24841, ensure that teams are properly configured with restricted accounts and update to a patched version of FleetDM.

3

Which versions of FleetDM are affected by CVE-2022-24841?

All versions of FleetDM using the teams feature prior to version 4.13 are affected by CVE-2022-24841.

4

What is the primary impact of CVE-2022-24841?

The primary impact of CVE-2022-24841 is an authorization bypass that could allow unauthorized users access to restricted resources.

5

Is my FleetDM instance safe from CVE-2022-24841 if I don't use teams?

Yes, instances of FleetDM that do not utilize the teams feature are not affected by CVE-2022-24841.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203