CVE-2024-32470

Source
https://cve.org/CVERecord?id=CVE-2024-32470
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-32470.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-32470
Related
  • GHSA-pm57-hcm8-38gw
  • GHSA-r95p-fqqv-fppc
Published
2024-04-18T15:05:26.408Z
Modified
2026-04-02T10:51:16.274976Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Tolgee' API keys created by server admin users bypass the permission check
Details

Tolgee is an open-source localization platform. When API key created by admin user is used it bypasses the permission check at all. This error was introduced in v3.57.2 and immediately fixed in v3.57.4.

Database specific
{
    "cwe_ids": [
        "CWE-863"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/32xxx/CVE-2024-32470.json"
}
References

Affected packages

Git / github.com/tolgee/tolgee-platform

Affected ranges

Type
GIT
Repo
https://github.com/tolgee/tolgee-platform
Events

Affected versions

v3.*
v3.57.2
v3.57.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-32470.json"