CVE-2024-39322

aimeos/ai-admin-jsonadm is the Aimeos e-commerce JSON API for administrative tasks. In versions prior to 2020.10.13, 2021.10.6, 2022.10.3, 2023.10.4, and 2024.4.2, improper access control allows editors to remove admin group and locale configuration in the Aimeos backend. Versions 2020.10.13, 2021.10.6, 2022.10.3, 2023.10.4, and 2024.4.2 contain a fix for the issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:aimeos_project:ai-controller-frontend:*:*:*:*:*:*:*:*
cpe:2.3:a:aimeos_project:ai-controller-frontend:*:*:*:*:*:*:*:*
cpe:2.3:a:aimeos_project:ai-controller-frontend:*:*:*:*:*:*:*:*
cpe:2.3:a:aimeos_project:ai-controller-frontend:*:*:*:*:*:*:*:*
cpe:2.3:a:aimeos_project:ai-controller-frontend:2024.04.1:*:*:*:*:*:*:*

History

21 Nov 2024, 09:27

Type Values Removed Values Added
References () https://github.com/aimeos/ai-admin-jsonadm/commit/02a063fbd616d4e0a5aaf89f1642a856aa5ac5a5 - Patch () https://github.com/aimeos/ai-admin-jsonadm/commit/02a063fbd616d4e0a5aaf89f1642a856aa5ac5a5 - Patch
References () https://github.com/aimeos/ai-admin-jsonadm/commit/16d013d0e28cecd19781f434d83fabebcc78cdc2 - Patch () https://github.com/aimeos/ai-admin-jsonadm/commit/16d013d0e28cecd19781f434d83fabebcc78cdc2 - Patch
References () https://github.com/aimeos/ai-admin-jsonadm/commit/4c966e02bd52589c3c9382777cfe170eddf17b00 - Patch () https://github.com/aimeos/ai-admin-jsonadm/commit/4c966e02bd52589c3c9382777cfe170eddf17b00 - Patch
References () https://github.com/aimeos/ai-admin-jsonadm/commit/640954243ce85c2c303a00dd6481ed39b3d218fb - Patch () https://github.com/aimeos/ai-admin-jsonadm/commit/640954243ce85c2c303a00dd6481ed39b3d218fb - Patch
References () https://github.com/aimeos/ai-admin-jsonadm/commit/7d1c05e8368b0a6419820fe402deac9960500026 - Patch () https://github.com/aimeos/ai-admin-jsonadm/commit/7d1c05e8368b0a6419820fe402deac9960500026 - Patch
References () https://github.com/aimeos/ai-admin-jsonadm/security/advisories/GHSA-8fj2-587w-5whr - Third Party Advisory () https://github.com/aimeos/ai-admin-jsonadm/security/advisories/GHSA-8fj2-587w-5whr - Third Party Advisory

15 Oct 2024, 20:47

Type Values Removed Values Added
First Time Aimeos Project
Aimeos Project ai-controller-frontend
CPE cpe:2.3:a:aimeos_project:ai-controller-frontend:*:*:*:*:*:*:*:*
cpe:2.3:a:aimeos_project:ai-controller-frontend:2024.04.1:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
References () https://github.com/aimeos/ai-admin-jsonadm/commit/02a063fbd616d4e0a5aaf89f1642a856aa5ac5a5 - () https://github.com/aimeos/ai-admin-jsonadm/commit/02a063fbd616d4e0a5aaf89f1642a856aa5ac5a5 - Patch
References () https://github.com/aimeos/ai-admin-jsonadm/commit/16d013d0e28cecd19781f434d83fabebcc78cdc2 - () https://github.com/aimeos/ai-admin-jsonadm/commit/16d013d0e28cecd19781f434d83fabebcc78cdc2 - Patch
References () https://github.com/aimeos/ai-admin-jsonadm/commit/4c966e02bd52589c3c9382777cfe170eddf17b00 - () https://github.com/aimeos/ai-admin-jsonadm/commit/4c966e02bd52589c3c9382777cfe170eddf17b00 - Patch
References () https://github.com/aimeos/ai-admin-jsonadm/commit/640954243ce85c2c303a00dd6481ed39b3d218fb - () https://github.com/aimeos/ai-admin-jsonadm/commit/640954243ce85c2c303a00dd6481ed39b3d218fb - Patch
References () https://github.com/aimeos/ai-admin-jsonadm/commit/7d1c05e8368b0a6419820fe402deac9960500026 - () https://github.com/aimeos/ai-admin-jsonadm/commit/7d1c05e8368b0a6419820fe402deac9960500026 - Patch
References () https://github.com/aimeos/ai-admin-jsonadm/security/advisories/GHSA-8fj2-587w-5whr - () https://github.com/aimeos/ai-admin-jsonadm/security/advisories/GHSA-8fj2-587w-5whr - Third Party Advisory

03 Jul 2024, 12:53

Type Values Removed Values Added
Summary
  • (es) aimeos/ai-admin-jsonadm es la API JSON de comercio electrónico de Aimeos para tareas administrativas. En versiones anteriores a 2020.10.13, 2021.10.6, 2022.10.3, 2023.10.4 y 2024.4.2, el control de acceso inadecuado permite a los editores eliminar el grupo de administración y la configuración local en el backend de Aimeos. Las versiones 2020.10.13, 2021.10.6, 2022.10.3, 2023.10.4 y 2024.4.2 contienen una solución para el problema.

02 Jul 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-02 21:15

Updated : 2024-11-21 09:27


NVD link : CVE-2024-39322

Mitre link : CVE-2024-39322

CVE.ORG link : CVE-2024-39322


JSON object : View

Products Affected

aimeos_project

  • ai-controller-frontend
CWE
CWE-863

Incorrect Authorization

NVD-CWE-noinfo