Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-8gwj-68w6-7v6c: OroCommerce Customer Portal Incorrect Customer and Customer Group Frontend Menus pages visibility

Back-office users can access information about Customer and Customer User menus, bypassing ACL security restrictions due to insufficient security checks.

ghsa
#git
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2023-32064

OroCommerce Customer Portal Incorrect Customer and Customer Group Frontend Menus pages visibility

Moderate severity GitHub Reviewed Published Nov 27, 2023 in oroinc/orocommerce • Updated Nov 27, 2023

Package

composer oro/customer-portal (Composer)

Affected versions

>= 4.2.0, <= 4.2.8

>= 5.0.0, < 5.0.11

>= 5.1.0, < 5.1.1

Patched versions

5.0.11

5.1.1

Back-office users can access information about Customer and Customer User menus, bypassing ACL security restrictions due to insufficient security checks.

References

  • GHSA-8gwj-68w6-7v6c

Published to the GitHub Advisory Database

Nov 27, 2023

Last updated

Nov 27, 2023

Related news

CVE-2023-32064: Incorrect Customer and Customer Group Frontend Menus pages visibility

OroCommerce package with customer portal and non authenticated visitor website base features. Back-office users can access information about Customer and Customer User menus, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.11 and 5.1.1.

ghsa: Latest News

GHSA-6gf2-ffq8-gcww: GHSL-2024-288: SickChill open redirect in login