Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS0zZzQzLXhmcnctcHY1bc4AA8IS
eZ Platform User data disclosure
In eZ Platform v2.3.x it is possible to bypass permission checks in a particular case. This means user data such as name and email (but not passwords or password hashes) can be read by unauthenticated users. This affects only v2.3.x. If you use v2.2.x or older you are not affected.
To install, use Composer to update "ezsystems/repository-forms" to the "Resolving versions" mentioned above, or apply this patch manually:
https://github.com/ezsystems/repository-forms/commit/ea82e136ec1ea40aca714abb79cc8e5bfece01e8
Have you found a security bug in eZ Publish or eZ Platform? See how to report it responsibly here: https://doc.ez.no/Security
Permalink: https://github.com/advisories/GHSA-3g43-xfrw-pv5mJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zZzQzLXhmcnctcHY1bc4AA8IS
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: 7 months ago
Updated: 7 months ago
Identifiers: GHSA-3g43-xfrw-pv5m
References:
- https://github.com/ezsystems/repository-forms/commit/ea82e136ec1ea40aca714abb79cc8e5bfece01e8
- https://github.com/FriendsOfPHP/security-advisories/blob/master/ezsystems/repository-forms/2018-11-20-1.yaml
- https://web.archive.org/web/20210614184249/http://share.ez.no/community-project/security-advisories/ezsa-2018-007-user-data-disclosure
- http://share.ez.no/community-project/security-advisories/ezsa-2018-007-user-data-disclosure
- https://github.com/advisories/GHSA-3g43-xfrw-pv5m
Blast Radius: 0.0
Affected Packages
packagist:ezsystems/repository-forms
Dependent packages: 23Dependent repositories: 73
Downloads: 659,219 total
Affected Version Ranges: >= 2.3.0, < 2.3.2.1
Fixed in: 2.3.2.1
All affected versions: 2.3.0, 2.3.1, 2.3.2, 2.3.3, 2.4.0, 2.4.1, 2.4.2, 2.4.3, 2.4.4, 2.4.5, 2.5.0, 2.5.1, 2.5.2, 2.5.3, 2.5.4, 2.5.5, 2.5.6, 2.5.7, 2.5.8, 2.5.9, 2.5.10, 2.5.11, 2.5.12, 2.5.13, 2.5.14, 2.5.15
All unaffected versions: 0.1.0, 0.1.1, 0.1.2, 1.0.0, 1.0.1, 1.1.0, 1.2.0, 1.2.1, 1.3.0, 1.4.0, 1.4.1, 1.5.0, 1.5.1, 1.5.2, 1.5.3, 1.5.4, 1.5.5, 1.5.6, 1.6.0, 1.7.0, 1.8.0, 1.9.0, 1.9.1, 1.10.0, 1.11.0, 1.11.1, 1.11.2, 1.11.3, 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2