Headline
GHSA-g6jc-xrc3-4wwq: Ibexa DXP users with the Company admin role can assign any role to any user
Critical severity. Users with the Company admin role (introduced by the company account feature in v4) can assign any role to any user. This also applies to any other user that has the role / assign policy. Any subtree limitation in place does not have any effect.
The role / assign policy is typically only given to administrators, which limits the scope in most cases, but please verify who has this policy in your installaton. The fix ensures that subtree limitations are working as intended.
- GitHub Advisory Database
- GitHub Reviewed
- GHSA-g6jc-xrc3-4wwq
Ibexa DXP users with the Company admin role can assign any role to any user
Critical severity GitHub Reviewed Published Nov 10, 2022 in ibexa/admin-ui • Updated Nov 10, 2022
Vulnerability details Dependabot alerts 0
Package
composer ibexa/admin-ui (Composer)
Affected versions
>= 4.2.0, < 4.2.3
Patched versions
4.2.3
Description
Critical severity. Users with the Company admin role (introduced by the company account feature in v4) can assign any role to any user. This also applies to any other user that has the role / assign policy. Any subtree limitation in place does not have any effect.
The role / assign policy is typically only given to administrators, which limits the scope in most cases, but please verify who has this policy in your installaton. The fix ensures that subtree limitations are working as intended.
References
- GHSA-g6jc-xrc3-4wwq
- ibexa/admin-ui@e34abb0
- https://developers.ibexa.co/security-advisories/ibexa-sa-2022-009-critical-vulnerabilities-in-graphql-role-assignment-ct-editing-and-drafts-tooltips
glye published the maintainer security advisory
Nov 10, 2022
Severity
Critical
Weaknesses
No CWEs
CVE ID
No known CVE
GHSA ID
GHSA-g6jc-xrc3-4wwq
Source code
ibexa/admin-ui
Checking history
See something to contribute? Suggest improvements for this vulnerability.