CVE-2024-32466 affects Tolgee, an open-source localization platform, where translation data could be accessed via specific API endpoints even when the API key lacked the necessary "translation.view" scope. This medium-severity vulnerability (CVSS 4.3) has a low impact, allowing unauthorized viewing of translation data by authenticated users whose API keys were generated by someone with the "translation.view" permission. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability. The issue has been resolved in Tolgee version 3.57.2.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.57.2CPE matchmatch criteria | cpe:2.3:a:tolgee:tolgee:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.