Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-9wwg-r3c7-4vfg: Pimcore Admin UI has Two Factor Authentication disabled for non admin security firewalls

Impact

AdminBundle\Security\PimcoreUserTwoFactorCondition introduced in v11 disable the two factor authentication for all non-admin security firewalls.

An authenticated user can access the system without having to provide the 2 factor credentials.

Patches

Apply patch https://patch-diff.githubusercontent.com/raw/pimcore/admin-ui-classic-bundle/pull/345.patch

Workarounds

Upgrade to version 1.2.2 or apply the patch manually.

ghsa
#vulnerability#web#git#auth

Skip to content

Sign up

CVE-2023-49075

    • Actions

      Automate any workflow

    • Packages

      Host and manage packages

    • Security

      Find and fix vulnerabilities

    • Codespaces

      Instant dev environments

    • Copilot

      Write better code with AI

    • Code review

      Manage code changes

    • Issues

      Plan and track work

    • Discussions

      Collaborate outside of code

Explore

*   All features
*   Documentation
*   GitHub Skills
*   Blog
  • For

    • Enterprise
    • Teams
    • Startups
    • Education

    By Solution

    • CI/CD & Automation
    • DevOps
    • DevSecOps

    Resources

    • Learning Pathways
    • White papers, Ebooks, Webinars
    • Customer Stories
    • Partners
    • GitHub Sponsors

      Fund open source developers

*   The ReadME Project
    
    GitHub community articles
    

Repositories

*   Topics
*   Trending
*   Collections
  • Pricing

Search code, repositories, users, issues, pull requests…

Provide feedback

We read every piece of feedback, and take your input very seriously.

Include my email address so I can be contacted

Saved searches****Use saved searches to filter your results more quickly

Sign in

Sign up

  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2023-49075

Pimcore Admin UI has Two Factor Authentication disabled for non admin security firewalls

High severity GitHub Reviewed Published Nov 27, 2023 in pimcore/admin-ui-classic-bundle

Vulnerability details Dependabot alerts 0

Package

composer pimcore/admin-ui-classic-bundle (Composer)

Affected versions

< 1.2.2

Patched versions

1.2.2

Description

Impact

AdminBundle\Security\PimcoreUserTwoFactorCondition introduced in v11 disable the two factor authentication for all non-admin security firewalls.

An authenticated user can access the system without having to provide the 2 factor credentials.

Patches

Apply patch https://patch-diff.githubusercontent.com/raw/pimcore/admin-ui-classic-bundle/pull/345.patch

Workarounds

Upgrade to version 1.2.2 or apply the patch manually.

References

  • GHSA-9wwg-r3c7-4vfg
  • pimcore/admin-ui-classic-bundle#345
  • pimcore/admin-ui-classic-bundle@e412b05
  • https://patch-diff.githubusercontent.com/raw/pimcore/admin-ui-classic-bundle/pull/345.patch

dvesh3 published to pimcore/admin-ui-classic-bundle

Nov 27, 2023

Published to the GitHub Advisory Database

Nov 27, 2023

Reviewed

Nov 27, 2023

Severity

High

8.4

/ 10

CVSS base metrics

Attack vector

Network

Attack complexity

Low

Privileges required

High

User interaction

Required

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

Weaknesses

No CWEs

CVE ID

CVE-2023-49075

GHSA ID

GHSA-9wwg-r3c7-4vfg

Source code

pimcore/admin-ui-classic-bundle

Checking history

See something to contribute? Suggest improvements for this vulnerability.

Related news

CVE-2023-49075: Two Factor Authentication disabled for non admin security firewalls

The Admin Classic Bundle provides a Backend UI for Pimcore. `AdminBundle\Security\PimcoreUserTwoFactorCondition` introduced in v11 disable the two factor authentication for all non-admin security firewalls. An authenticated user can access the system without having to provide the two factor credentials. This issue has been patched in version 1.2.2.

ghsa: Latest News

GHSA-hqmp-g7ph-x543: TunnelVision - decloaking VPNs using DHCP