Incorrect Authorization
CVE-2022-48367
Summary
Object state limitation is a policy you can use in your roles to limit access to content based on specific object state values. Due to a flawed earlier update, these limitations were ineffective in releases made since February 16th, 2022. They would grant access to the given content regardless of the object state. Depending on how your frontend is designed, knowing the URL to the content may or may not be required to access it. If you are using object state limitations in your roles, this issue is critical in ezsystems/ezpublish-kernel 7.5.x prior to 7.5.28, ibexa/core 4.0.x prior to 4.0.5, 4.1.x prior to 4.1.2 and ezsystems/ezplatform-kernel 1.3.x prior to 1.3.17. Please apply the fix as soon as possible.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- NONE
- HIGH
- HIGH
CWE-863 - Incorrect Authorization
Authorization is a security mechanism performed by an application to grant or deny access to the requested resources by verifying the privileges of the user. When an application lacks effective authorization mechanisms, it enables unauthorized users to gain unintended privileges and illegitimate access to resources. Such a vulnerability may result in exposure of sensitive information, denial of service, arbitrary code execution, and complete system takeover.
References
Advisory Timeline
- Published