HIGH
GHSA-44m4-9cjp-j587
IBX-1392: Image filenames sanitization
Quick fix
GHSA-44m4-9cjp-j587 — ezsystems/ezpublish-kernel: upgrade to the fixed version with the command below.
composer require ezsystems/ezpublish-kernel:^7.5.26Details
ezsystems/ezpublish-kernel versions 7.5.* before 7.5.26 are vulnerable to certain injection attacks and unauthorized access to some image files.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/ezsystems/ezpublish-kernel
Introduced in:
7.5.0Fixed in: 7.5.26Fix
composer require ezsystems/ezpublish-kernel:^7.5.26References
- https://github.com/ezsystems/ezpublish-kernel/security/advisories/GHSA-44m4-9cjp-j587[WEB]
- https://developers.ibexa.co/security-advisories/ibexa-sa-2022-001-image-filenames-sanitization[WEB]
- https://github.com/ezsystems/ezpublish-kernel[WEB]
- https://github.com/ezsystems/ezpublish-kernel/releases/tag/v7.5.26[WEB]