CVE-2024-32466

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/04/2024
Last modified:
11/09/2025

Description

Tolgee is an open-source localization platform. For the `/v2/projects/translations` and `/v2/projects/{projectId}/translations` endpoints, translation data was returned even when API key was missing `translation.view` scope. However, it was impossible to fetch the data when user was missing this scope. So this is only relevant for API keys generated by users permitted to `translation.view`. This vulnerability is fixed in v3.57.2<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tolgee:tolgee:*:*:*:*:*:*:*:* 3.57.2 (excluding)