Products
Government
Resources
Community
Company
Partners
Sign In / Join
Sign In
Advisories
Ibexa Kernel for eZ Platform ignoring object state limitation policy granting access to certain links
Go Back
severity
critical
date
March 12, 2023
Affecting
ezpublish-kernel versions 7.5.0 upto 7.5.28
CVE
CVE-2022-48367
CVE type
Improper Preservation of Permissions
CVSS
6.8
CVSS V3 Vector
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
References
GHSA-5x4f-7xgq-r42x
ibexa advisory