Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-6f58-j323-6472: pimcore/admin-ui-classic-bundle Unverified Password Change

Impact

As old password can be set as new password , it is considered as password policy violation.

Pimcore is not enforcing strict password policy which allow attacker to set old password as new password

Proof of Concept

  1. Go to Admin link
  2. login and click on -> "User | My Profile".
  3. Go to change password now put old password as new password and click save.

Patches

https://github.com/pimcore/admin-ui-classic-bundle/commit/498ac77e54541177be27b0c710e387c47b3836ea.patch

Workarounds

Update to version 1.2.0 or apply this patches manually https://github.com/pimcore/admin-ui-classic-bundle/commit/498ac77e54541177be27b0c710e387c47b3836ea.patch

References

https://huntr.com/bounties/b031199d-192a-46e5-8c02-f7284ad74021/

ghsa
#git

Package

composer pimcore/admin-ui-classic-bundle (Composer)

Affected versions

< 1.2.0

Patched versions

1.2.0

Description

Impact

As old password can be set as new password , it is considered as password policy violation.

Pimcore is not enforcing strict password policy which allow attacker to set old password as new password

Proof of Concept

  1. Go to Admin link
  2. login and click on -> "User | My Profile".
  3. Go to change password now put old password as new password and click save.

Patches

https://github.com/pimcore/admin-ui-classic-bundle/commit/498ac77e54541177be27b0c710e387c47b3836ea.patch

Workarounds

Update to version 1.2.0 or apply this patches manually
https://github.com/pimcore/admin-ui-classic-bundle/commit/498ac77e54541177be27b0c710e387c47b3836ea.patch

References

https://huntr.com/bounties/b031199d-192a-46e5-8c02-f7284ad74021/

References

  • GHSA-6f58-j323-6472
  • https://nvd.nist.gov/vuln/detail/CVE-2023-5844
  • pimcore/admin-ui-classic-bundle@498ac77
  • https://huntr.com/bounties/b031199d-192a-46e5-8c02-f7284ad74021

dvesh3 published to pimcore/admin-ui-classic-bundle

Oct 30, 2023

Published to the GitHub Advisory Database

Oct 31, 2023

Reviewed

Oct 31, 2023

Related news

CVE-2023-5844: [Improvement]: Check if new password is NOT the same as the old one w… · pimcore/admin-ui-classic-bundle@498ac77

Unverified Password Change in GitHub repository pimcore/admin-ui-classic-bundle prior to 1.2.0.