Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-1703: [Task] Optimized composite index key (#14636) · pimcore/pimcore@765832f

Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.20.

CVE
#xss#git

@@ -455,6 +455,14 @@ public function saveAction(Request $request)

$class->rename($values[‘name’]);

}

if ($values[‘compositeIndices’]) {

foreach ($values[‘compositeIndices’] as $index => $compositeIndex) {

if ($compositeIndex[‘index_key’] !== ($sanitizedKey = preg_replace('/[^a-za-z0-9_\-+]/’, '’, $compositeIndex[‘index_key’]))) {

$values[‘compositeIndices’][$index][‘index_key’] = $sanitizedKey;

}

}

}

unset($values[‘creationDate’]);

unset($values[‘userOwner’]);

unset($values[‘layoutDefinitions’]);

Related news

GHSA-4f25-2x2c-vg6v: pimcore is vulnerable to cross-site scripting in Composite indices key field

### Impact Pimcore is vulnerable to Cross site scripting vulnerability in classes module. ### Patches Update to version 10.5.20. ### Workarounds Apply the patch https://github.com/pimcore/pimcore/commit/765832f0dc5f6cfb296a82e089b701066f27bcef.patch manually.

GHSA-3r5c-h7g6-cqw7: pimcore is vulnerable to cross-site scripting in classes module

Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.20.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907