Users could hide their account from team leads

Affected versions

  • Kimai versions > 2.4 are affected by this security issue
  • The issue has been fixed in Kimai 2.68.0
  • Severity: Low
  • A CVE ID is requested, pending assignment

Description

Any logged-in user could edit two protected settings on their own profile. This allowed them to hide their account and time records from their team lead, and to cancel a password change that an administrator had required.

  • Any user account is affected, no special role or permission is needed
  • The two settings were available in the user’s own “Edit profile” page and through the API
  • System account: users could mark their own account as a system account. System accounts are hidden from team leads, so a user could remove their profile and timesheets from the view of the team lead who is responsible for them. The account is also hidden in reports and dropdowns.
  • Password reset: users could remove the “requires password reset” flag from their own account. This undid an administrator’s request to change the password, for example after a suspected credential leak.
  • No data from other users could be read or changed

Solution

Both settings are now only available to users who are allowed to manage the roles of the edited account. With the default permissions, regular users and team leads can no longer change these settings on their own profile, while administrators can still manage them for other users.

Users should update to 2.68.0 or newer.

Credits

  • Reported by: AzureADTrent
  • Patched by: kevinpapst
Top