VDB
Sign up
HIGH

GHSA-2w9p-xxqr-h253

eZ Platform Object Injection in SiteAccessMatchListener

Quick fix

GHSA-2w9p-xxqr-h253 — ezsystems/ezplatform-kernel: upgrade to the fixed version with the command below.

composer require ezsystems/ezplatform-kernel:^1.0.3

Details

This Security Advisory is about an object injection vulnerability in the SiteAccessMatchListener of eZ Platform, which could lead to remote code execution (RCE), a very serious threat. All sites may be affected.

Update: There are bugs introduced by this fix, particularly but not limited to compound siteaccess matchers. These have been fixed in ezsystems/ezplatform-kernel v1.0.3, and in ezsystems/ezpublish-kernel v7.5.8, v6.13.6.4, and v5.4.15.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/ezsystems/ezplatform-kernel
Introduced in: 1.0.0Fixed in: 1.0.3
Fixcomposer require ezsystems/ezplatform-kernel:^1.0.3

References