HIGH8.8
GHSA-hq76-662x-7mw4
Pimcore includes vulnerable PHPOffice/PhpSpreadsheet
Quick fix
GHSA-hq76-662x-7mw4 — pimcore/data-importer: upgrade to the fixed version with the command below.
composer require pimcore/data-importer:^1.8.9Details
### Summary Pimcore 10.6.x and Enterprise 10.6.x versions currently depend on PHPOffice/PhpSpreadsheet version 1.x, which has recently been identified with a security vulnerability (CVE-2024-45048). To mitigate this issue, it is recommended to update to the latest version 2.2.2. For more details, please refer to the official advisory: [GHSA-ghg6-32f9-2jp7](https://github.com/advisories/GHSA-ghg6-32f9-2jp7).
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/pimcore/data-importer
Introduced in:
0Fixed in: 1.8.9Fix
composer require pimcore/data-importer:^1.8.9Packagist/pimcore/data-importer
Introduced in:
1.9.0Fixed in: 1.9.3Fix
composer require pimcore/data-importer:^1.9.3Packagist/pimcore/admin-ui-classic-bundle
Introduced in:
0Fixed in: 1.3.11Fix
composer require pimcore/admin-ui-classic-bundle:^1.3.11Packagist/pimcore/admin-ui-classic-bundle
Introduced in:
1.4.0Fixed in: 1.4.7Fix
composer require pimcore/admin-ui-classic-bundle:^1.4.7Packagist/pimcore/admin-ui-classic-bundle
Introduced in:
1.5.0Fixed in: 1.5.4Fix
composer require pimcore/admin-ui-classic-bundle:^1.5.4Packagist/pimcore/pimcore
Introduced in:
10.6.9.0Fixed in: 10.6.9.12Fix
composer require pimcore/pimcore:^10.6.9.12Packagist/pimcore/pimcore
Introduced in:
11.1.0.0Fixed in: 11.1.6.11Fix
composer require pimcore/pimcore:^11.1.6.11