Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jr83-m233-gg6p

Опубликовано: 04 мар. 2024
Источник: github
Github: Прошло ревью
CVSS3: 6.8

Описание

Sulu grants access to pages regardless of role permissions

Impact

What kind of vulnerability is it? Who is impacted?

Access to pages is granted regardless of role permissions for webspaces which have a security system configured and permission check enabled. Webspaces without do not have this issue.

Patches

Has the problem been patched? What versions should users upgrade to?

The problem is patched with Version 2.4.17 and 2.5.13.

Workarounds

Is there a way for users to fix or remediate the vulnerability without upgrading?

Remove following lines from vendor/symfony/security-http/HttpUtils.php:

- // Shortcut if request has already been matched before - if ($request->attributes->has('_route')) { - return $path === $request->attributes->get('_route'); - }

Or do not install symfony/security-http versions greater equal than v5.4.30 or v6.3.6.

References

Are there any links users can visit to find out more?

Currently no references.

Пакеты

Наименование

sulu/sulu

composer
Затронутые версииВерсия исправления

>= 2.2.0, < 2.4.17

2.4.17

Наименование

sulu/sulu

composer
Затронутые версииВерсия исправления

>= 2.5.0-alpha1, < 2.5.13

2.5.13

EPSS

Процентиль: 36%
0.00155
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.8
nvd
почти 2 года назад

Sulu is a PHP content management system. Starting in verson 2.2.0 and prior to version 2.4.17 and 2.5.13, access to pages is granted regardless of role permissions for webspaces which have a security system configured and permission check enabled. Webspaces without do not have this issue. The problem is patched in versions 2.4.17 and 2.5.13. Some workarounds are available. One may apply the patch to `vendor/symfony/security-http/HttpUtils.php` manually or avoid installing `symfony/security-http` versions greater equal than `v5.4.30` or `v6.3.6`.

EPSS

Процентиль: 36%
0.00155
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-863