Lucene search

K
githubGitHub Advisory DatabaseGHSA-H5V2-WRHP-5V35
HistoryMar 12, 2023 - 6:30 a.m.

Access control issue in ezsystems/ezpublish-kernel

2023-03-1206:30:21
CWE-862
GitHub Advisory Database
github.com
13
access control
ezpublish-kernel
object state limitations
policy
flawed update

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.002 Low

EPSS

Percentile

60.7%

Access control based on object state is mishandled. This is a policy you can use in your roles to limit access to content based on specific object state values. Due to a flawed earlier update, these limitations were ineffective in releases made since February 16th 2022. They would grant access to the given content regardless of the object state. Depending on how your frontent is designed, knowing the URL to the content may or may not be required to access it. If you are using object state limitations in your roles, this issue is critical. Please apply the fix as soon as possible.

Affected configurations

Vulners
Node
ezsystemsezpublish-kernelRange<7.5.28
CPENameOperatorVersion
ezsystems/ezpublish-kernellt7.5.28

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.002 Low

EPSS

Percentile

60.7%

Related for GHSA-H5V2-WRHP-5V35