aimeos/ai-admin-graphql
Aimeos Admin GraphQL API extension
Activity
- Latest release
- 4mo ago
- Total releases
- 43
- Cadence
- ~21 days
- Last 12 months
- 4
Reach
- Stars
- —
Details
- License
- LGPL-3.0
- First release
- Oct 05, 2022
| Version | Released | |
|---|---|---|
2026.04.1
major
| ||
2024.10.4
patch
| ||
2025.10.2
patch
| ||
2025.10.1
minor
| ||
2025.07.1
minor
| ||
2025.04.1
major
| ||
2024.10.3
patch
| ||
2023.10.9
patch
| ||
2024.10.2
patch
| ||
2024.10.1
minor
| ||
2024.07.2
patch
| ||
2023.10.8
patch
| ||
2024.07.1
minor
1 CVE
CVE-2024-47173
GHSA-qxgx-hvg3-v92w
Oct 24, 2024
ai-admin-graphql has a Denial of service vulnerability in SaaS and marketplace setups
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
All SaaS and marketplace setups using Aimeos version from 2024.04 up to 2024.07.1 are affected by a potential denial of service attack Affected versions
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.04.7
2024.07.1
Fixed in
2024.07.2
References Updated Oct 24, 2024 · Source: OSV.dev | ||
2024.04.7
patch
1 CVE
CVE-2024-47173
GHSA-qxgx-hvg3-v92w
Oct 24, 2024
ai-admin-graphql has a Denial of service vulnerability in SaaS and marketplace setups
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
All SaaS and marketplace setups using Aimeos version from 2024.04 up to 2024.07.1 are affected by a potential denial of service attack Affected versions
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.04.7
2024.07.1
Fixed in
2024.07.2
References Updated Oct 24, 2024 · Source: OSV.dev | ||
2022.10.11
patch
| ||
2023.10.7
patch
| ||
2024.04.6
patch
1 CVE
CVE-2024-47173
GHSA-qxgx-hvg3-v92w
Oct 24, 2024
ai-admin-graphql has a Denial of service vulnerability in SaaS and marketplace setups
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
All SaaS and marketplace setups using Aimeos version from 2024.04 up to 2024.07.1 are affected by a potential denial of service attack Affected versions
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.04.7
2024.07.1
Fixed in
2024.07.2
References Updated Oct 24, 2024 · Source: OSV.dev | ||
2024.04.5
patch
2 CVEs
CVE-2024-47173
GHSA-qxgx-hvg3-v92w
Oct 24, 2024
ai-admin-graphql has a Denial of service vulnerability in SaaS and marketplace setups
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
All SaaS and marketplace setups using Aimeos version from 2024.04 up to 2024.07.1 are affected by a potential denial of service attack Affected versions
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.04.7
2024.07.1
Fixed in
2024.07.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-39323
GHSA-vc7j-99jw-jrqm
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
High
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 12 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
Fixed in
2022.10.10
2023.10.6
2024.04.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2024.04.4
patch
2 CVEs
CVE-2024-47173
GHSA-qxgx-hvg3-v92w
Oct 24, 2024
ai-admin-graphql has a Denial of service vulnerability in SaaS and marketplace setups
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
All SaaS and marketplace setups using Aimeos version from 2024.04 up to 2024.07.1 are affected by a potential denial of service attack Affected versions
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.04.7
2024.07.1
Fixed in
2024.07.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-39323
GHSA-vc7j-99jw-jrqm
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
High
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 12 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
Fixed in
2022.10.10
2023.10.6
2024.04.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2024.04.3
patch
2 CVEs
CVE-2024-47173
GHSA-qxgx-hvg3-v92w
Oct 24, 2024
ai-admin-graphql has a Denial of service vulnerability in SaaS and marketplace setups
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
All SaaS and marketplace setups using Aimeos version from 2024.04 up to 2024.07.1 are affected by a potential denial of service attack Affected versions
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.04.7
2024.07.1
Fixed in
2024.07.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-39323
GHSA-vc7j-99jw-jrqm
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
High
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 12 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
Fixed in
2022.10.10
2023.10.6
2024.04.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2022.10.10
patch
| ||
2023.10.6
patch
| ||
2024.04.2
patch
2 CVEs
CVE-2024-47173
GHSA-qxgx-hvg3-v92w
Oct 24, 2024
ai-admin-graphql has a Denial of service vulnerability in SaaS and marketplace setups
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
All SaaS and marketplace setups using Aimeos version from 2024.04 up to 2024.07.1 are affected by a potential denial of service attack Affected versions
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.04.7
2024.07.1
Fixed in
2024.07.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-39323
GHSA-vc7j-99jw-jrqm
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
High
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 12 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
Fixed in
2022.10.10
2023.10.6
2024.04.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2024.04.1
major
3 CVEs
CVE-2024-47173
GHSA-qxgx-hvg3-v92w
Oct 24, 2024
ai-admin-graphql has a Denial of service vulnerability in SaaS and marketplace setups
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
All SaaS and marketplace setups using Aimeos version from 2024.04 up to 2024.07.1 are affected by a potential denial of service attack Affected versions
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.04.7
2024.07.1
Fixed in
2024.07.2
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2024-39324
GHSA-jj68-cp4v-98qf
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
3.8
/ 10
Low
Network
Low
High
None
Unchanged
None
Low
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and 2024.4.2 contain a patch for the issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 8 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
Fixed in
2022.10.10
2023.10.6
2024.04.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39323
GHSA-vc7j-99jw-jrqm
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
High
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 12 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
Fixed in
2022.10.10
2023.10.6
2024.04.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2023.10.5
patch
2 CVEs
CVE-2024-39324
GHSA-jj68-cp4v-98qf
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
3.8
/ 10
Low
Network
Low
High
None
Unchanged
None
Low
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and 2024.4.2 contain a patch for the issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 8 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
Fixed in
2022.10.10
2023.10.6
2024.04.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39323
GHSA-vc7j-99jw-jrqm
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
High
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 12 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
Fixed in
2022.10.10
2023.10.6
2024.04.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2023.10.4
patch
2 CVEs
CVE-2024-39324
GHSA-jj68-cp4v-98qf
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
3.8
/ 10
Low
Network
Low
High
None
Unchanged
None
Low
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and 2024.4.2 contain a patch for the issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 8 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
Fixed in
2022.10.10
2023.10.6
2024.04.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39323
GHSA-vc7j-99jw-jrqm
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
High
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 12 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
Fixed in
2022.10.10
2023.10.6
2024.04.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2023.10.3
patch
2 CVEs
CVE-2024-39324
GHSA-jj68-cp4v-98qf
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
3.8
/ 10
Low
Network
Low
High
None
Unchanged
None
Low
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and 2024.4.2 contain a patch for the issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 8 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
Fixed in
2022.10.10
2023.10.6
2024.04.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39323
GHSA-vc7j-99jw-jrqm
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
High
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 12 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
Fixed in
2022.10.10
2023.10.6
2024.04.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2023.10.2
patch
2 CVEs
CVE-2024-39324
GHSA-jj68-cp4v-98qf
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
3.8
/ 10
Low
Network
Low
High
None
Unchanged
None
Low
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and 2024.4.2 contain a patch for the issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 8 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
Fixed in
2022.10.10
2023.10.6
2024.04.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39323
GHSA-vc7j-99jw-jrqm
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
High
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 12 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
Fixed in
2022.10.10
2023.10.6
2024.04.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2023.10.1
minor
2 CVEs
CVE-2024-39324
GHSA-jj68-cp4v-98qf
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
3.8
/ 10
Low
Network
Low
High
None
Unchanged
None
Low
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and 2024.4.2 contain a patch for the issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 8 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
Fixed in
2022.10.10
2023.10.6
2024.04.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39323
GHSA-vc7j-99jw-jrqm
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
High
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 12 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
Fixed in
2022.10.10
2023.10.6
2024.04.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2023.07.2
patch
2 CVEs
CVE-2024-39324
GHSA-jj68-cp4v-98qf
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
3.8
/ 10
Low
Network
Low
High
None
Unchanged
None
Low
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and 2024.4.2 contain a patch for the issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 8 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
Fixed in
2022.10.10
2023.10.6
2024.04.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39323
GHSA-vc7j-99jw-jrqm
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
High
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 12 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
Fixed in
2022.10.10
2023.10.6
2024.04.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2023.07.1
minor
2 CVEs
CVE-2024-39324
GHSA-jj68-cp4v-98qf
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
3.8
/ 10
Low
Network
Low
High
None
Unchanged
None
Low
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and 2024.4.2 contain a patch for the issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 8 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
Fixed in
2022.10.10
2023.10.6
2024.04.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39323
GHSA-vc7j-99jw-jrqm
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
High
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 12 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
Fixed in
2022.10.10
2023.10.6
2024.04.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2022.10.9
patch
2 CVEs
CVE-2024-39324
GHSA-jj68-cp4v-98qf
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
3.8
/ 10
Low
Network
Low
High
None
Unchanged
None
Low
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and 2024.4.2 contain a patch for the issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 8 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
Fixed in
2022.10.10
2023.10.6
2024.04.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39323
GHSA-vc7j-99jw-jrqm
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
High
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 12 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
Fixed in
2022.10.10
2023.10.6
2024.04.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2023.04.3
patch
2 CVEs
CVE-2024-39324
GHSA-jj68-cp4v-98qf
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
3.8
/ 10
Low
Network
Low
High
None
Unchanged
None
Low
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and 2024.4.2 contain a patch for the issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 8 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
Fixed in
2022.10.10
2023.10.6
2024.04.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39323
GHSA-vc7j-99jw-jrqm
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
High
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 12 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
Fixed in
2022.10.10
2023.10.6
2024.04.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2022.10.8
patch
2 CVEs
CVE-2024-39324
GHSA-jj68-cp4v-98qf
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
3.8
/ 10
Low
Network
Low
High
None
Unchanged
None
Low
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and 2024.4.2 contain a patch for the issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 8 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
Fixed in
2022.10.10
2023.10.6
2024.04.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39323
GHSA-vc7j-99jw-jrqm
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
High
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 12 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
Fixed in
2022.10.10
2023.10.6
2024.04.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2023.04.2
patch
2 CVEs
CVE-2024-39324
GHSA-jj68-cp4v-98qf
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
3.8
/ 10
Low
Network
Low
High
None
Unchanged
None
Low
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and 2024.4.2 contain a patch for the issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 8 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
Fixed in
2022.10.10
2023.10.6
2024.04.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39323
GHSA-vc7j-99jw-jrqm
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
High
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 12 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
Fixed in
2022.10.10
2023.10.6
2024.04.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2023.04.1
major
2 CVEs
CVE-2024-39324
GHSA-jj68-cp4v-98qf
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
3.8
/ 10
Low
Network
Low
High
None
Unchanged
None
Low
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and 2024.4.2 contain a patch for the issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 8 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
Fixed in
2022.10.10
2023.10.6
2024.04.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39323
GHSA-vc7j-99jw-jrqm
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
High
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 12 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
Fixed in
2022.10.10
2023.10.6
2024.04.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2022.10.7
patch
2 CVEs
CVE-2024-39324
GHSA-jj68-cp4v-98qf
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
3.8
/ 10
Low
Network
Low
High
None
Unchanged
None
Low
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and 2024.4.2 contain a patch for the issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 8 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
Fixed in
2022.10.10
2023.10.6
2024.04.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39323
GHSA-vc7j-99jw-jrqm
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
High
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 12 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
Fixed in
2022.10.10
2023.10.6
2024.04.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2022.10.6
patch
2 CVEs
CVE-2024-39324
GHSA-jj68-cp4v-98qf
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
3.8
/ 10
Low
Network
Low
High
None
Unchanged
None
Low
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and 2024.4.2 contain a patch for the issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 8 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
Fixed in
2022.10.10
2023.10.6
2024.04.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39323
GHSA-vc7j-99jw-jrqm
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
High
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 12 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
Fixed in
2022.10.10
2023.10.6
2024.04.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2022.10.5
patch
2 CVEs
CVE-2024-39324
GHSA-jj68-cp4v-98qf
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
3.8
/ 10
Low
Network
Low
High
None
Unchanged
None
Low
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and 2024.4.2 contain a patch for the issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 8 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
Fixed in
2022.10.10
2023.10.6
2024.04.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39323
GHSA-vc7j-99jw-jrqm
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
High
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 12 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
Fixed in
2022.10.10
2023.10.6
2024.04.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2022.10.4
patch
2 CVEs
CVE-2024-39324
GHSA-jj68-cp4v-98qf
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
3.8
/ 10
Low
Network
Low
High
None
Unchanged
None
Low
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and 2024.4.2 contain a patch for the issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 8 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
Fixed in
2022.10.10
2023.10.6
2024.04.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39323
GHSA-vc7j-99jw-jrqm
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
High
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 12 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
Fixed in
2022.10.10
2023.10.6
2024.04.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2022.10.3
patch
2 CVEs
CVE-2024-39324
GHSA-jj68-cp4v-98qf
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
3.8
/ 10
Low
Network
Low
High
None
Unchanged
None
Low
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and 2024.4.2 contain a patch for the issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 8 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
Fixed in
2022.10.10
2023.10.6
2024.04.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39323
GHSA-vc7j-99jw-jrqm
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
High
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 12 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
Fixed in
2022.10.10
2023.10.6
2024.04.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2022.10.2
patch
2 CVEs
CVE-2024-39324
GHSA-jj68-cp4v-98qf
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
3.8
/ 10
Low
Network
Low
High
None
Unchanged
None
Low
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and 2024.4.2 contain a patch for the issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 8 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
Fixed in
2022.10.10
2023.10.6
2024.04.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39323
GHSA-vc7j-99jw-jrqm
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
High
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 12 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
Fixed in
2022.10.10
2023.10.6
2024.04.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2022.10.1
initial
2 CVEs
CVE-2024-39324
GHSA-jj68-cp4v-98qf
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
3.8
/ 10
Low
Network
Low
High
None
Unchanged
None
Low
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed in the JQAdm front end. Versions 2022.10.10, 2023.10.6, and 2024.4.2 contain a patch for the issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 8 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
Fixed in
2022.10.10
2023.10.6
2024.04.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39323
GHSA-vc7j-99jw-jrqm
Jul 02, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
High
Low
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability allows an editor to modify and take over an admin account in the back end. Versions 2022.10.10, 2023.10.6, and 2024.04.6 fix this issue. Affected versions
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2023.04.1
2023.04.2
2023.04.3
+ 12 more Show less
2023.07.1
2023.07.2
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
Fixed in
2022.10.10
2023.10.6
2024.04.6
References
Updated Sep 10, 2026 · Source: OSV.dev |