{"id":"CVE-2024-39322","summary":"aimeos/ai-admin-jsonadm improper access control vulnerability allows editors to remove required records","details":"aimeos/ai-admin-jsonadm is the Aimeos e-commerce JSON API for administrative tasks. In versions prior to 2020.10.13, 2021.10.6, 2022.10.3, 2023.10.4, and 2024.4.2, improper access control allows editors to remove admin group and locale configuration in the Aimeos backend. Versions 2020.10.13, 2021.10.6, 2022.10.3, 2023.10.4, and 2024.4.2 contain a fix for the issue.\n","aliases":["GHSA-8fj2-587w-5whr"],"modified":"2026-08-12T03:51:45.851820809Z","published":"2024-07-02T20:19:01.919Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/39xxx/CVE-2024-39322.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/39xxx/CVE-2024-39322.json"},{"type":"ADVISORY","url":"https://github.com/aimeos/ai-admin-jsonadm/security/advisories/GHSA-8fj2-587w-5whr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-39322"},{"type":"FIX","url":"https://github.com/aimeos/ai-admin-jsonadm/commit/02a063fbd616d4e0a5aaf89f1642a856aa5ac5a5"},{"type":"FIX","url":"https://github.com/aimeos/ai-admin-jsonadm/commit/16d013d0e28cecd19781f434d83fabebcc78cdc2"},{"type":"FIX","url":"https://github.com/aimeos/ai-admin-jsonadm/commit/4c966e02bd52589c3c9382777cfe170eddf17b00"},{"type":"FIX","url":"https://github.com/aimeos/ai-admin-jsonadm/commit/640954243ce85c2c303a00dd6481ed39b3d218fb"},{"type":"FIX","url":"https://github.com/aimeos/ai-admin-jsonadm/commit/7d1c05e8368b0a6419820fe402deac9960500026"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/aimeos/ai-admin-jsonadm","events":[{"introduced":"0"},{"fixed":"fb793220484a4a90c06f84e695a0940c690af01f"},{"introduced":"e5f9b97e0675b42b22bf3cfc51a834e46b3f07b9"},{"fixed":"e604d5b016494f936671cf6afef8ce36de3307c3"},{"introduced":"3d04a222c7887c5cfdce04449c309942e309b1ba"},{"fixed":"24068e0e065a793c1b9e80737498b7ac7c6866d2"},{"introduced":"85ecd7a5024794940c45f198a90c67322c0a154e"},{"fixed":"50cf668a348551acf2675d93c6a1137609b08489"},{"introduced":"8c9975951acb1889354e7829353c899ddf4d5dac"},{"fixed":"02a063fbd616d4e0a5aaf89f1642a856aa5ac5a5"},{"fixed":"16d013d0e28cecd19781f434d83fabebcc78cdc2"},{"fixed":"4c966e02bd52589c3c9382777cfe170eddf17b00"},{"fixed":"640954243ce85c2c303a00dd6481ed39b3d218fb"},{"fixed":"7d1c05e8368b0a6419820fe402deac9960500026"}],"database_specific":{"cpe":["cpe:2.3:a:aimeos_project:ai-controller-frontend:*:*:*:*:*:*:*:*","cpe:2.3:a:aimeos_project:ai-controller-frontend:2024.04.1:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"2020.10.13"},{"introduced":"2021.04.1"},{"fixed":"2021.10.6"},{"introduced":"2022.04.1"},{"fixed":"2022.10.3"},{"introduced":"2023.04.1"},{"fixed":"2023.10.4"},{"introduced":"2024.04.1"},{"last_affected":"2024.04.1"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"]}}],"versions":["2024.04.1","= 2024.04.1","2020.10.12","2021.10.5","2022.10.2","2023.10.3","2023.10.2","2023.10.1","2022.10.1","2021.10.4","2021.10.3","2021.10.2","2021.10.1","2020.10.11","2020.10.10","2020.10.9","2020.10.8","2020.10.7","2020.10.6","2020.10.5","2020.10.4","2020.10.3","2020.10.2","2020.10.1","2019.04.1","2018.01.1","2017.07.1","2017.01.1","2016.07.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-39322.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H"}]}