Budget values appeared in exports and API results for users who must not see them
Affected versions
- Kimai versions <= 2.65.0 are affected by this security issue
- The issue has been fixed in Kimai 2.66.0
- Severity: Low
- A CVE ID is requested, pending assignment
Description
Kimai has separate permissions that control whether you can see the money and time budgets of customers, projects, and activities. These permissions were applied to the screens in the web interface, but not to the administration exports and the API, so users who were only allowed to see the listings could still obtain the budget values that the interface hides from them.
- Required permissions: to view the customer, project or activity listing.
- Affected were the spreadsheet exports of the customer, project and activity administration screens, and the API responses for customers, projects, and activities.
- The exposed values are the money budget, the time budget, and the budget type.
- The listings in the web interface behaved correctly and hid the budget columns from these users.
- The issue is limited to reading values. Budgets could not be changed through this, and no other data was exposed.
Solution
The budget permissions are now attached to the export fields themselves, instead of relying on every export and endpoint to filter them out. Exports keep the budget columns but leave a cell empty when you’re not allowed to see that value.
The API returns each budget field only when you hold the matching permission — monetary and time permissions are checked per record, so a team lead sees the budgets of their own projects and empty values for all others in the same file or response.
Users should update to 2.66.0 or newer.
Credits
- Reported by: tr4cebit
- Patched by: kevinpapst
Kimai