GHSA-9g2q-w3w2-vf7q: Kimai has Missing Voter Check that Allows Cross-Team Timesheet Manipulation
Any ROLE_TEAMLEAD user can enumerate, read, modify, and permanently delete timesheets belonging to any other user in the system — regardless of team membership. This enables data destruction (deleted billable hours), data tampering (forged timesheet durations), and full authorization bypass on timesheet resources. Verified against Kimai 2.52.0.
References
Code Behaviors & Features
Detect and mitigate GHSA-9g2q-w3w2-vf7q with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →