CVE-2024-55073: High severity hay-kot mealie vulnerability
A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows users to edit their own profile in order to give themselves more permissions or to change their household.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-55073?
CVE-2024-55073 is rated as a high severity vulnerability due to its potential for allowing unauthorized privilege escalation.
How do I fix CVE-2024-55073?
To fix CVE-2024-55073, update to the latest patched version of hay-kot mealie where object level authorization checks are properly implemented.
What systems are affected by CVE-2024-55073?
CVE-2024-55073 affects hay-kot mealie versions prior to 2.2.0, specifically the API endpoint /api/users/{user-id}.
What type of vulnerability is CVE-2024-55073?
CVE-2024-55073 is categorized as a Broken Object Level Authorization vulnerability.
Can CVE-2024-55073 lead to data compromise?
Yes, CVE-2024-55073 can potentially lead to data compromise as it allows users to escalate permissions and alter their profile.