CVE-2024-25634: IDOR make user can read e-mail log sent by other events
alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, an attacker can access data from other organizers. The attacker can use a specially crafted request to receive the e-mail log sent by other events. Version 2.0-M4-2402 fixes this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
alf.ioto a version that resolves this vulnerability.Fixed in 2.0-M4-2402
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25634?
CVE-2024-25634 is considered a medium severity vulnerability due to its potential impact on data confidentiality.
How do I fix CVE-2024-25634?
To fix CVE-2024-25634, upgrade to version 2.0-M4-2402 or later of the alf.io ticket reservation system.
What systems are affected by CVE-2024-25634?
CVE-2024-25634 affects alf.io versions prior to 2.0-M4-2402.
What type of data can be accessed through CVE-2024-25634?
An attacker can access the email log from other events within the alf.io system due to CVE-2024-25634.
Is CVE-2024-25634 an open source vulnerability?
Yes, CVE-2024-25634 affects alf.io, which is an open source ticket reservation system.