CVE-2023-32075
MEDIUM4.3EPSS 0.01%Pimcore vulnerable to Business Logic Errors via Customer automation rules
發布日:2023/5/11修改日:2024/2/16
描述
### Impact Business Logic Errors in the Conditions tab since the counter can be a negative number. This vulnerability is capable of the unlogic in the counter value in the Conditions tab. ### Patches Update to version 3.3.9 or apply this patch manually https://github.com/pimcore/customer-data-framework/commit/e3f333391582d9309115e6b94e875367d0ea7163.patch ### Workarounds Apply https://github.com/pimcore/customer-data-framework/commit/e3f333391582d9309115e6b94e875367d0ea7163.patch manually. ### References https://huntr.dev/bounties/cecd7800-a996-4f3a-8689-e1c2a1e0248a/
受影響套件(1)
- Packagist/pimcore/customer-management-framework-bundlefrom 0, < 3.3.9
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
參考連結(6)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2023-32075
- PATCHhttps://github.com/pimcore/customer-data-framework
- WEBhttps://github.com/pimcore/customer-data-framework/commit/e3f333391582d9309115e6b94e875367d0ea7163.patch
- WEBhttps://github.com/pimcore/customer-data-framework/releases/tag/v3.3.9
- WEBhttps://github.com/pimcore/customer-data-framework/security/advisories/GHSA-x99j-r8vv-gwwj
- WEBhttps://huntr.dev/bounties/cecd7800-a996-4f3a-8689-e1c2a1e0248a