VDB
Sign up
MEDIUM6.8

GHSA-jr83-m233-gg6p

Sulu grants access to pages regardless of role permissions

Quick fix

GHSA-jr83-m233-gg6p — sulu/sulu: upgrade to the fixed version with the command below.

composer require sulu/sulu:^2.4.17

Details

### Impact

_What kind of vulnerability is it? Who is impacted?_

Access to pages is granted regardless of role permissions for webspaces which have a security system configured and permission check enabled. Webspaces without do not have this issue.

### Patches

Has the problem been patched? What versions should users upgrade to?

The problem is patched with Version `2.4.17` and `2.5.13`.

### Workarounds

_Is there a way for users to fix or remediate the vulnerability without upgrading?_

Remove following lines from `vendor/symfony/security-http/HttpUtils.php`:

``` - // Shortcut if request has already been matched before - if ($request->attributes->has('_route')) { - return $path === $request->attributes->get('_route'); - } ```

Or do not install `symfony/security-http` versions greater equal than `v5.4.30` or `v6.3.6`.

### References

_Are there any links users can visit to find out more?_

Currently no references.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/sulu/sulu
Introduced in: 2.2.0Fixed in: 2.4.17
Fixcomposer require sulu/sulu:^2.4.17
Packagist/sulu/sulu
Introduced in: 2.5.0-alpha1Fixed in: 2.5.13
Fixcomposer require sulu/sulu:^2.5.13

References