CVE Vulnerabilities

CVE-2024-25635

Improper Authorization of Index Containing Sensitive Information

Published: Feb 19, 2024 | Modified: Dec 18, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, organization owners can view the generated API KEY and USERS of other organization owners using the http://192.168.26.128:8080/admin/api/users/<user_id> endpoint, which exposes the details of the provided user ID. This may also expose the API KEY in the username of the user. Version 2.0-M4-2402 fixes this issue.

Weakness

The product creates a search index of private or sensitive documents, but it does not properly limit index access to actors who are authorized to see the original information.

Affected Software

Name Vendor Start Version End Version
Alf Alf * 2.0-m4-2402 (excluding)

References