Логотип exploitDog
bind:CVE-2023-49075
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-49075

Количество 2

Количество 2

nvd логотип

CVE-2023-49075

около 2 лет назад

The Admin Classic Bundle provides a Backend UI for Pimcore. `AdminBundle\Security\PimcoreUserTwoFactorCondition` introduced in v11 disable the two factor authentication for all non-admin security firewalls. An authenticated user can access the system without having to provide the two factor credentials. This issue has been patched in version 1.2.2.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-9wwg-r3c7-4vfg

около 2 лет назад

Pimcore Admin UI has Two Factor Authentication disabled for non admin security firewalls

CVSS3: 8.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-49075

The Admin Classic Bundle provides a Backend UI for Pimcore. `AdminBundle\Security\PimcoreUserTwoFactorCondition` introduced in v11 disable the two factor authentication for all non-admin security firewalls. An authenticated user can access the system without having to provide the two factor credentials. This issue has been patched in version 1.2.2.

CVSS3: 8.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-9wwg-r3c7-4vfg

Pimcore Admin UI has Two Factor Authentication disabled for non admin security firewalls

CVSS3: 8.4
0%
Низкий
около 2 лет назад

Уязвимостей на страницу