Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-394j-x37r-2q27: Ibexa DXP users with the Company admin role can assign any role to any user

Critical severity. Users with the Company admin role (introduced by the company account feature in v4) can assign any role to any user. This also applies to any other user that has the role / assign policy. Any subtree limitation in place does not have any effect.

The role / assign policy is typically only given to administrators, which limits the scope in most cases, but please verify who has this policy in your installaton. The fix ensures that subtree limitations are working as intended.

ghsa
#vulnerability#git
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. GHSA-394j-x37r-2q27

Ibexa DXP users with the Company admin role can assign any role to any user

Critical severity GitHub Reviewed Published Nov 10, 2022 in ibexa/core

Vulnerability details Dependabot alerts 0

Package

composer ibexa/core (Composer)

Affected versions

>= 4.2.0, < 4.2.3

Patched versions

4.2.3

Description

Critical severity. Users with the Company admin role (introduced by the company account feature in v4) can assign any role to any user. This also applies to any other user that has the role / assign policy. Any subtree limitation in place does not have any effect.

The role / assign policy is typically only given to administrators, which limits the scope in most cases, but please verify who has this policy in your installaton. The fix ensures that subtree limitations are working as intended.

References

  • GHSA-394j-x37r-2q27
  • ibexa/core@da3642c
  • https://developers.ibexa.co/security-advisories/ibexa-sa-2022-009-critical-vulnerabilities-in-graphql-role-assignment-ct-editing-and-drafts-tooltips

glye published the maintainer security advisory

Nov 10, 2022

Severity

Critical

Weaknesses

No CWEs

CVE ID

No known CVE

GHSA ID

GHSA-394j-x37r-2q27

Source code

ibexa/core

Checking history

See something to contribute? Suggest improvements for this vulnerability.

ghsa: Latest News

GHSA-mj5r-x73q-fjw6: SPEmailHandler-PHP has Potential Abuse for Sending Arbitrary Emails