Headline
GHSA-6f58-j323-6472: pimcore/admin-ui-classic-bundle Unverified Password Change
Impact
As old password can be set as new password , it is considered as password policy violation.
Pimcore is not enforcing strict password policy which allow attacker to set old password as new password
Proof of Concept
- Go to Admin link
- login and click on -> "User | My Profile".
- Go to change password now put old password as new password and click save.
Patches
https://github.com/pimcore/admin-ui-classic-bundle/commit/498ac77e54541177be27b0c710e387c47b3836ea.patch
Workarounds
Update to version 1.2.0 or apply this patches manually https://github.com/pimcore/admin-ui-classic-bundle/commit/498ac77e54541177be27b0c710e387c47b3836ea.patch
References
https://huntr.com/bounties/b031199d-192a-46e5-8c02-f7284ad74021/
Package
composer pimcore/admin-ui-classic-bundle (Composer)
Affected versions
< 1.2.0
Patched versions
1.2.0
Description
Impact
As old password can be set as new password , it is considered as password policy violation.
Pimcore is not enforcing strict password policy which allow attacker to set old password as new password
Proof of Concept
- Go to Admin link
- login and click on -> "User | My Profile".
- Go to change password now put old password as new password and click save.
Patches
https://github.com/pimcore/admin-ui-classic-bundle/commit/498ac77e54541177be27b0c710e387c47b3836ea.patch
Workarounds
Update to version 1.2.0 or apply this patches manually
https://github.com/pimcore/admin-ui-classic-bundle/commit/498ac77e54541177be27b0c710e387c47b3836ea.patch
References
https://huntr.com/bounties/b031199d-192a-46e5-8c02-f7284ad74021/
References
- GHSA-6f58-j323-6472
- https://nvd.nist.gov/vuln/detail/CVE-2023-5844
- pimcore/admin-ui-classic-bundle@498ac77
- https://huntr.com/bounties/b031199d-192a-46e5-8c02-f7284ad74021
dvesh3 published to pimcore/admin-ui-classic-bundle
Oct 30, 2023
Published to the GitHub Advisory Database
Oct 31, 2023
Reviewed
Oct 31, 2023
Related news
Unverified Password Change in GitHub repository pimcore/admin-ui-classic-bundle prior to 1.2.0.