GHSA-965r-9cg9-g42p
Valtimo backend libraries allows objects in the object-api to be accessed and modified by unauthorized users
Quick fix
GHSA-965r-9cg9-g42p — com.ritense.valtimo:object-management: upgrade to the fixed version with the command below.
# pom.xml: bump <version>12.13.0.RELEASE</version> for com.ritense.valtimo:object-managementDetails
### Impact All objects for which an object-management configuration exists can be listed, viewed, edited, created or deleted by unauthorised users.
If object-urls are exposed via other channels, the contents of these objects can be viewed independent of object-management configurations.
### Attack requirements The following conditions have to be met in order to perform this attack: - A user must be logged in - No relevant application roles are required - At least one object-type must be configured via object-management - The scope of the attack is limited to objects that are configured via object-management. - The value of `showInDataMenu` is irrelevant for this attack
### Patches This issue was patched in version 12.13.0.RELEASE.
### Workarounds It is possible to override the endpoint security as defined in `ObjectenApiHttpSecurityConfigurer` and `ObjectManagementHttpSecurityConfigurer`. Depending on the implementation, this could result in loss of functionality.
Are you affected?
Enter the version of the package you're using.
Affected packages
11.0.0.RELEASENo fixed version published yet for com.ritense.valtimo:objecten-api (maven). Pin to a known-safe version or switch to an alternative.
11.0.0.RELEASENo fixed version published yet for com.ritense.valtimo:object-management (maven). Pin to a known-safe version or switch to an alternative.
12.0.0.RELEASEFixed in: 12.13.0.RELEASE# pom.xml: bump <version>12.13.0.RELEASE</version> for com.ritense.valtimo:object-management12.0.0.RELEASEFixed in: 12.13.0.RELEASE# pom.xml: bump <version>12.13.0.RELEASE</version> for com.ritense.valtimo:objecten-apiReferences
- https://github.com/valtimo-platform/valtimo-backend-libraries/security/advisories/GHSA-965r-9cg9-g42p[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-48881[ADVISORY]
- https://github.com/valtimo-platform/valtimo-backend-libraries/commit/6ab04b30d3dab816bfea32d40ba50e5dd4517272[WEB]
- https://github.com/valtimo-platform/valtimo-backend-libraries[PACKAGE]