CVE-2024-55072: Medium severity hay-kot mealie vulnerability
A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows users to edit their own profile in order to give themselves more permissions or to change their household.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-55072?
CVE-2024-55072 is classified as a high-severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2024-55072?
To fix CVE-2024-55072, ensure proper access controls are implemented on the /api/users/{user-id} endpoint to restrict user permissions.
Who is affected by CVE-2024-55072?
CVE-2024-55072 affects users of hay-kot mealie v2.2.0 who can exploit broken object level authorization.
What does CVE-2024-55072 allow an attacker to do?
CVE-2024-55072 allows an attacker to edit their own profile to gain additional permissions or modify household settings.
Is CVE-2024-55072 being actively exploited?
There is currently no public information indicating active exploitation of CVE-2024-55072, but it poses a significant risk if left unaddressed.