CVE-2022-48365
Company admin role gives excessive privileges in eZ Platform Ibexa
7.2
HIGH
CVSS 3.1
EPSS 0.86%
描述
Users with the Company admin role (introduced by the company account feature in v4) can assign any role to any user. This also applies to any other user that has the role / assign policy. Any subtree limitation in place does not have any effect. The role / assign policy is typically only given to administrators, which limits the scope in most cases, but please verify who has this policy in your installaton. The fix ensures that subtree limitations are working as intended.
如何修補 CVE-2022-48365
要修補 CVE-2022-48365,請將受影響套件升級到下列已修補版本。
- —升級至 1.3.26 或更新版本
- —升級至 1.3.26 或更新版本
- —升級至 7.5.30 或更新版本
- —升級至 7.5.30 或更新版本
CVE-2022-48365 正在被利用嗎?
低 — EPSS 為 0.9%,目前沒有觀察到大規模利用活動。
受影響套件(4)
- >= 1.3.0, < 1.3.26
- >= 1.3.0, < 1.3.26
- >= 7.5.0, < 7.5.30
- >= 7.5.0, < 7.5.30
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.2 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |