Timesheet rates were returned by the API to users who must not see them

Affected versions

  • Kimai versions <= 2.65.0 are affected by this security issue
  • The issue has been fixed in Kimai 2.66.0
  • Severity: Low
  • A CVE ID is requested, pending assignment

Description

Kimai has separate permissions that control who can see the money values on a timesheet. The web interface, the exports, the reports, and the revenue widgets all respect them, but the API returned the rate fields.

  • Every timesheet response of the API was affected.
  • The exposed values are: the calculated rate, the internal rate, the hourly rate, and the fixed rate.
  • Which records a user can see was always enforced correctly, this concerns additional fields on records the user can already read, not access to other people’s records.
  • The issue is limited to reading values: nothing could be created, changed, or deleted through it, and it requires a valid login or API token.

Solution

The rate fields were removed from the serialization groups that every API response uses, and a new exclusion rule now checks the rate permission for each individual record before the values are added. It applies the same rule as the listing, the export, and the reporting, so a response can contain the rates of your own records and leave them out for records you’re not allowed to see them for.

For API clients running under a plain user account, this is a breaking change — the rate fields are no longer part of their responses. See the UPGRADING notes for details.

Users should update to 2.66.0 or newer.

Credits

  • Reported by: arpitjain099
  • Patched by: kevinpapst
Top