CRITICAL9.8
GHSA-q8cr-xphm-7gfv
Akeneo PIM vulnerable to shell injection in the mass edition
Quick fix
GHSA-q8cr-xphm-7gfv — akeneo/pim-community-dev: upgrade to the fixed version with the command below.
composer require akeneo/pim-community-dev:^1.4.28Details
Akeneo PIM CE and EE <1.6.6, <1.5.15, <1.4.28 are vulnerable to shell injection in the mass edition, resulting in remote execution.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/akeneo/pim-community-dev
Introduced in:
1.4Fixed in: 1.4.28Fix
composer require akeneo/pim-community-dev:^1.4.28Packagist/akeneo/pim-community-dev
Introduced in:
1.5Fixed in: 1.5.15Fix
composer require akeneo/pim-community-dev:^1.5.15Packagist/akeneo/pim-community-dev
Introduced in:
1.6Fixed in: 1.6.6Fix
composer require akeneo/pim-community-dev:^1.6.6References
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000009[ADVISORY]
- https://github.com/akeneo/pim-community-dev[PACKAGE]
- https://github.com/akeneo/pim-community-dev/blob/1.5/CHANGELOG-1.5.md#bug-fixes-2[WEB]
- https://github.com/akeneo/pim-community-dev/blob/master/CHANGELOG-1.4.md#bug-fixes[WEB]
- https://github.com/akeneo/pim-community-dev/blob/master/CHANGELOG-1.6.md#bug-fixes-2[WEB]