GHSA-6f58-j323-6472
pimcore/admin-ui-classic-bundle Unverified Password Change
Quick fix
GHSA-6f58-j323-6472 — pimcore/admin-ui-classic-bundle: upgrade to the fixed version with the command below.
composer require pimcore/admin-ui-classic-bundle:^1.2.0-RC1Details
### Impact As old password can be set as new password , it is considered as password policy violation.
Pimcore is not enforcing strict password policy which allow attacker to set old password as new password
Proof of Concept 1. Go to Admin link 2. login and click on -> "User | My Profile". 3. Go to change password now put old password as new password and click save.
### Patches https://github.com/pimcore/admin-ui-classic-bundle/commit/498ac77e54541177be27b0c710e387c47b3836ea.patch
### Workarounds Update to version 1.2.0 or apply this patches manually https://github.com/pimcore/admin-ui-classic-bundle/commit/498ac77e54541177be27b0c710e387c47b3836ea.patch
### References https://huntr.com/bounties/b031199d-192a-46e5-8c02-f7284ad74021/
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.2.0-RC1composer require pimcore/admin-ui-classic-bundle:^1.2.0-RC1References
- https://github.com/pimcore/admin-ui-classic-bundle/security/advisories/GHSA-6f58-j323-6472[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-5844[ADVISORY]
- https://github.com/pimcore/admin-ui-classic-bundle/commit/498ac77e54541177be27b0c710e387c47b3836ea[WEB]
- https://github.com/pimcore/admin-ui-classic-bundle[PACKAGE]
- https://huntr.com/bounties/b031199d-192a-46e5-8c02-f7284ad74021[WEB]