CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-55070

Medium Severity
Mealie
SVRS
37/100

CVSSv3
3.1/10

EPSS
0.00024/1

CVE-2024-55070 is a security vulnerability in hay-kot mealie v2.2.0, specifically a Broken Object Level Authorization issue. This flaw allows group managers to inadvertently edit their own permissions within the /households/permissions component. With an SVRS score of 37, the threat is currently considered moderate, suggesting that while the vulnerability exists, immediate action might not be critical, but monitoring is advised. This could lead to unauthorized permission changes by group managers, affecting access control within the application. Although the CVSS score is low, it's crucial to track and address this vulnerability to prevent potential escalation of privileges or other unintended consequences. Resolving this access control issue will ensure that group managers cannot modify their own permissions, maintaining the integrity of the application. Ignoring this could lead to a situation where users elevate their own privileges beyond what is intended, which leads to data breaches.

No tags available
CVSS:3.1
AV:N
AC:H
PR:L
UI:N
S:U
C:L
I:N
A:N
2025-03-27

2025-04-11

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

CVE-2024-55070 | hay-kot Mealie 2.2.0 /households/permissions (Issue 4593)
vuldb.com2025-03-28
CVE-2024-55070 | hay-kot Mealie 2.2.0 /households/permissions (Issue 4593) | A vulnerability was found in hay-kot Mealie 2.2.0. It has been declared as critical. This vulnerability affects unknown code of the file /households/permissions. The manipulation leads to permission issues. This vulnerability was named CVE-2024-55070. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
rss
forum
news

Social Media

CVE-2024-55070 A Broken Object Level Authorization vulnerability in the component /households/permissions of hay-kot mealie v2.2.0 allows group managers to edit their own permission… https://t.co/8FYbQe18rd
0
0
0

Affected Software

Configuration 1
TypeVendorProduct
AppMealiemealie

References

ReferenceLink
[email protected]https://github.com/mealie-recipes/mealie/issues/4593
[email protected]https://m10x.de/posts/2025/03/all-your-recipe-are-belong-to-us-part-3/3-broken-access-controls-leading-to-privilege-escalation-and-more-in-mealie/

CWE Details

CWE IDCWE NameDescription
CWE-862Missing AuthorizationThe software does not perform an authorization check when an actor attempts to access a resource or perform an action.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence