HIGH
GHSA-64vj-933f-6pm3
eZ Platform Object Injection in SiteAccessMatchListener
Quick fix
GHSA-64vj-933f-6pm3 — ezsystems/ezpublish-kernel: upgrade to the fixed version with the command below.
composer require ezsystems/ezpublish-kernel:^7.5.8Details
This Security Advisory is about an object injection vulnerability in the SiteAccessMatchListener of eZ Platform, which could lead to remote code execution (RCE), a very serious threat. All sites may be affected.
Update: There are bugs introduced by this fix, particularly but not limited to compound siteaccess matchers. These have been fixed in ezsystems/ezplatform-kernel v1.0.3, and in ezsystems/ezpublish-kernel v7.5.8, v6.13.6.4, and v5.4.15.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/ezsystems/ezpublish-kernel
Introduced in:
7.5.0Fixed in: 7.5.8Fix
composer require ezsystems/ezpublish-kernel:^7.5.8Packagist/ezsystems/ezpublish-kernel
Introduced in:
6.13.0Fixed in: 6.13.6.4Fix
composer require ezsystems/ezpublish-kernel:^6.13.6.4Packagist/ezsystems/ezpublish-kernel
Introduced in:
5.4.0Fixed in: 5.4.15Fix
composer require ezsystems/ezpublish-kernel:^5.4.15