Skip to content

eZ Platform User data disclosure

High severity GitHub Reviewed Published May 15, 2024 to the GitHub Advisory Database • Updated May 15, 2024

Package

composer ezsystems/repository-forms (Composer)

Affected versions

>= 2.3.0, < 2.3.2.1

Patched versions

2.3.2.1

Description

In eZ Platform v2.3.x it is possible to bypass permission checks in a particular case. This means user data such as name and email (but not passwords or password hashes) can be read by unauthenticated users. This affects only v2.3.x. If you use v2.2.x or older you are not affected.

To install, use Composer to update "ezsystems/repository-forms" to the "Resolving versions" mentioned above, or apply this patch manually:
ezsystems/repository-forms@ea82e13

Have you found a security bug in eZ Publish or eZ Platform? See how to report it responsibly here: https://doc.ez.no/Security

References

Published to the GitHub Advisory Database May 15, 2024
Reviewed May 15, 2024
Last updated May 15, 2024

Severity

High

Weaknesses

CVE ID

No known CVE

GHSA ID

GHSA-3g43-xfrw-pv5m
Checking history
See something to contribute? Suggest improvements for this vulnerability.