Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-vx35-f379-4q49: Pimcore Customer Management Framework vulnerable to Improper Authorization in Rules Controller

Impact

The product performs authorization checks incorrectly when an unauthorized actor tries to access a resource or perform an actions.

The attacker can view and freely perform actions to add, modify, or delete rules.

Patches

Update to version 3.4.1 or apply this patch manually https://github.com/pimcore/customer-data-framework/commit/f15668c86db254e86ba7ac895bc3cdd1a2a3cc45.patch

Workarounds

Apply https://github.com/pimcore/customer-data-framework/commit/f15668c86db254e86ba7ac895bc3cdd1a2a3cc45.patch manually.

References

https://huntr.dev/bounties/1dcb4f01-e668-4aa3-a6a3-838532e500c6/

ghsa
#vulnerability#git#auth

Skip to content

Sign up

CVE-2023-3574

    • Actions

      Automate any workflow

    • Packages

      Host and manage packages

    • Security

      Find and fix vulnerabilities

    • Codespaces

      Instant dev environments

    • Copilot

      Write better code with AI

    • Code review

      Manage code changes

    • Issues

      Plan and track work

    • Discussions

      Collaborate outside of code

Explore

*   All features
*   Documentation
*   GitHub Skills
*   Blog
  • For

    • Enterprise
    • Teams
    • Startups
    • Education

    By Solution

    • CI/CD & Automation
    • DevOps
    • DevSecOps

    Case Studies

    • Customer Stories
    • Resources
    • GitHub Sponsors

      Fund open source developers

*   The ReadME Project
    
    GitHub community articles
    

Repositories

*   Topics
*   Trending
*   Collections
  • Pricing

Search code, repositories, users, issues, pull requests…

Provide feedback

We read every piece of feedback, and take your input very seriously.

Include my email address so I can be contacted

Saved searches****Use saved searches to filter your results more quickly

Sign in

Sign up

  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2023-3574

Pimcore Customer Management Framework vulnerable to Improper Authorization in Rules Controller

Moderate severity GitHub Reviewed Published Jul 10, 2023 in pimcore/customer-data-framework • Updated Jul 10, 2023

Vulnerability details Dependabot alerts 0

Package

composer pimcore/customer-management-framework-bundle (Composer)

Affected versions

< 3.4.1

Patched versions

3.4.1

Description

Impact

The product performs authorization checks incorrectly when an unauthorized actor tries to access a resource or perform an actions.

The attacker can view and freely perform actions to add, modify, or delete rules.

Patches

Update to version 3.4.1 or apply this patch manually https://github.com/pimcore/customer-data-framework/commit/f15668c86db254e86ba7ac895bc3cdd1a2a3cc45.patch

Workarounds

Apply https://github.com/pimcore/customer-data-framework/commit/f15668c86db254e86ba7ac895bc3cdd1a2a3cc45.patch manually.

References

https://huntr.dev/bounties/1dcb4f01-e668-4aa3-a6a3-838532e500c6/

References

  • GHSA-vx35-f379-4q49
  • https://nvd.nist.gov/vuln/detail/CVE-2023-3574
  • pimcore/customer-data-framework@f15668c
  • https://github.com/pimcore/customer-data-framework/commit/f15668c86db254e86ba7ac895bc3cdd1a2a3cc45.patch
  • https://huntr.dev/bounties/1dcb4f01-e668-4aa3-a6a3-838532e500c6
  • https://huntr.dev/bounties/1dcb4f01-e668-4aa3-a6a3-838532e500c6/

dvesh3 published to pimcore/customer-data-framework

Jul 10, 2023

Published to the GitHub Advisory Database

Jul 10, 2023

Reviewed

Jul 10, 2023

Last updated

Jul 10, 2023

Severity

Moderate

6.3

/ 10

CVSS base metrics

Attack vector

Network

Attack complexity

Low

Privileges required

Low

User interaction

None

Scope

Unchanged

Confidentiality

Low

Integrity

Low

Availability

Low

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Weaknesses

CWE-285 CWE-863

CVE ID

CVE-2023-3574

GHSA ID

GHSA-vx35-f379-4q49

Source code

pimcore/customer-data-framework

Credits

  • aqngoc Reporter

Checking history

See something to contribute? Suggest improvements for this vulnerability.

Related news

CVE-2023-3574: Improper Authorization in "Customer automation rules" function in customer-data-framework

Improper Authorization in GitHub repository pimcore/customer-data-framework prior to 3.4.1.