CVE-2024-55070
Mealie
CVE-2024-55070 is a security vulnerability in hay-kot mealie v2.2.0, specifically a Broken Object Level Authorization issue. This flaw allows group managers to inadvertently edit their own permissions within the /households/permissions component. With an SVRS score of 37, the threat is currently considered moderate, suggesting that while the vulnerability exists, immediate action might not be critical, but monitoring is advised. This could lead to unauthorized permission changes by group managers, affecting access control within the application. Although the CVSS score is low, it's crucial to track and address this vulnerability to prevent potential escalation of privileges or other unintended consequences. Resolving this access control issue will ensure that group managers cannot modify their own permissions, maintaining the integrity of the application. Ignoring this could lead to a situation where users elevate their own privileges beyond what is intended, which leads to data breaches.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.