CVE-2022-24841: Improper Authorization in github.com/fleetdm/fleet
fleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams feature are affected by this authorization bypass issue. Fleet instances without teams, or with teams but without restricted team accounts are not affected. In affected versions a team admin can erroneously add themselves as admin, maintainer or observer on other teams. Users are advised to upgrade to version 4.13. There are no known workarounds for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-24841?
CVE-2022-24841 has been classified as a medium severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2022-24841?
To fix CVE-2022-24841, ensure that teams are properly configured with restricted accounts and update to a patched version of FleetDM.
Which versions of FleetDM are affected by CVE-2022-24841?
All versions of FleetDM using the teams feature prior to version 4.13 are affected by CVE-2022-24841.
What is the primary impact of CVE-2022-24841?
The primary impact of CVE-2022-24841 is an authorization bypass that could allow unauthorized users access to restricted resources.
Is my FleetDM instance safe from CVE-2022-24841 if I don't use teams?
Yes, instances of FleetDM that do not utilize the teams feature are not affected by CVE-2022-24841.