Lucene search

K
githubGitHub Advisory DatabaseGHSA-QQ2J-9PF8-G58C
HistoryMar 12, 2023 - 6:30 a.m.

Company admin role gives excessive privileges in eZ Platform Ibexa

2023-03-1206:30:21
CWE-269
GitHub Advisory Database
github.com
7
company admin role
excessive privileges
ez platform
ibexa
role assign policy
subtree limitations
software

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

52.6%

Users with the Company admin role (introduced by the company account feature in v4) can assign any role to any user. This also applies to any other user that has the role / assign policy. Any subtree limitation in place does not have any effect.

The role / assign policy is typically only given to administrators, which limits the scope in most cases, but please verify who has this policy in your installaton. The fix ensures that subtree limitations are working as intended.

Affected configurations

Vulners
Node
ezsystemsezplatform-kernelRange1.3.01.3.26
OR
ezsystemsezpublish-kernelRange7.5.07.5.30
VendorProductVersionCPE
ezsystemsezplatform-kernel*cpe:2.3:a:ezsystems:ezplatform-kernel:*:*:*:*:*:*:*:*
ezsystemsezpublish-kernel*cpe:2.3:a:ezsystems:ezpublish-kernel:*:*:*:*:*:*:*:*

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

52.6%

Related for GHSA-QQ2J-9PF8-G58C