CVE-2024-29200: API returns timesheet entries a user should not be authorized to view

Published Mar 28, 2024
·
Updated

Summary The permission viewothertimesheet performs differently for the Kimai UI and the API, thus returning unexpected data through the API.

Details When setting the viewothertimesheet permission to true, on the frontend, users can only see timesheet entries for teams they are a part of. When requesting all timesheets from the API, however, all timesheet entries are returned, regardless of whether the user shares team permissions or not.

Example: There are projects P1 and P2, Teams T1 and T2, users U1 and U2 and Timesheet entries E1 and E2. U1 is team leader of team T1 and has access to P1. U2 is in Team T2 and has access to both P1 and P2. U2 creates E1 for P1 and E2 for P2. In the UI, U1 with view othertimesheet perms sees E1 as he is a part of T1 that has access to P1. In the API, however, he has access to E1 and E2.

Additionally, if U1 is not a team leader T1, he does not see any timesheet from a user other than himself in the UI, but still all timesheets in the API.

PoC - Give a user viewothertimesheet permission - The result of the UI and the API call to /api/timesheets?user=all differs in the data that is being returned

Curl command: bash curl -X 'GET' \ 'https://kimai.instance.com/api/timesheets?user=all' \ -H 'accept: application/json' \ -H 'X-AUTH-USER: username' \ -H 'X-AUTH-TOKEN: apitoken'

Impact This is at least an insufficient granularity of access control weakness. People can see timesheet entries they are not supposed to. This greatly affects the confidentiality of timesheet entries.

Restricting API access to administrators is also not a valid solution, as API access is needed, for example, to use the mobile app.

Other sources

Kimai is a web-based multi-user time-tracking application. The permission viewothertimesheet performs differently for the Kimai UI and the API, thus returning unexpected data through the API. When setting the viewothertimesheet permission to true, on the frontend, users can only see timesheet entries for teams they are a part of. When requesting all timesheets from the API, however, all timesheet entries are returned, regardless of whether the user shares team permissions or not. This vulnerability is fixed in 2.13.0.

NVD

Affected Software

2 affected componentsFixes available
composer/kimai/kimai<2.13.0
2.13.0
Kimai Kimai<2.13.0

Event History

Mar 28, 2024
CVE Published
via MITRE·01:28 PM
Data Sourced
via MITRE·01:28 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
Affected Software
Mar 29, 2024
Advisory Published
via GitHub·07:05 PM

Frequently Asked Questions

1

What is the severity of CVE-2024-29200?

CVE-2024-29200 has a moderate severity as it affects user permission handling, potentially exposing sensitive timesheet data.

2

How do I fix CVE-2024-29200?

To fix CVE-2024-29200, upgrade Kimai to version 2.13.0 or later.

3

What software versions are affected by CVE-2024-29200?

CVE-2024-29200 affects Kimai versions prior to 2.13.0.

4

Can CVE-2024-29200 affect data integrity?

Yes, CVE-2024-29200 can lead to unauthorized data access, potentially compromising data integrity.

5

What permission is misconfigured in CVE-2024-29200?

The misconfigured permission in CVE-2024-29200 is `view_other_timesheet`, which behaves inconsistently between the UI and API.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203