ezsystems/ezpublish-legacy
eZ Publish Legacy (aka LegacyStack in 5.x. Is an updated version of eZ Publish 4.x cable of being combined with eZ Platform)
Activity
- Latest release
- 5y ago
- Total releases
- 78
- Cadence
- ~6 days
- Last 12 months
- 0
Reach
- Stars
- —
Details
- License
- unknown
- First release
- Apr 30, 2013
| Version | Released | |
|---|---|---|
v2019.03.6.1
patch
|
v2019.03.6.1
patch
Dependencies (31)
+ 23 more
Changelog
Compare changes
|
|
v2017.12.7.4
patch
|
v2017.12.7.4
patch
Dependencies (31)
+ 23 more
Changelog
Compare changes
|
|
v2019.03.6
patch
1 CVE
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2019.03.5.1
patch
1 CVE
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2017.12.7.3
patch
1 CVE
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2019.03.5
patch
2 CVEs
GHSA-39j2-4p9j-5w4j
May 15, 2024
Ez Platform Object Injection in legacy shop module
Medium
This Security Advisory is about a vulnerability in the Legacy shop module. A backend editor could perform object injection in discount rules. This would require backend access and permission to edit discount rules. While object injection in itself is a serious vulnerability, the permission requirement means that normally only administrators would be able to exploit it, that's why it was classified as Medium severity. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
+ 12 more Show less
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
Fixed in
5.4.14.2
2017.12.7.3
2019.3.5.1
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2017.12.7.2
patch
2 CVEs
GHSA-39j2-4p9j-5w4j
May 15, 2024
Ez Platform Object Injection in legacy shop module
Medium
This Security Advisory is about a vulnerability in the Legacy shop module. A backend editor could perform object injection in discount rules. This would require backend access and permission to edit discount rules. While object injection in itself is a serious vulnerability, the permission requirement means that normally only administrators would be able to exploit it, that's why it was classified as Medium severity. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
+ 12 more Show less
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
Fixed in
5.4.14.2
2017.12.7.3
2019.3.5.1
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2019.03.4.2
patch
2 CVEs
GHSA-39j2-4p9j-5w4j
May 15, 2024
Ez Platform Object Injection in legacy shop module
Medium
This Security Advisory is about a vulnerability in the Legacy shop module. A backend editor could perform object injection in discount rules. This would require backend access and permission to edit discount rules. While object injection in itself is a serious vulnerability, the permission requirement means that normally only administrators would be able to exploit it, that's why it was classified as Medium severity. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
+ 12 more Show less
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
Fixed in
5.4.14.2
2017.12.7.3
2019.3.5.1
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2019.03.4
patch
4 CVEs
GHSA-39j2-4p9j-5w4j
May 15, 2024
Ez Platform Object Injection in legacy shop module
Medium
This Security Advisory is about a vulnerability in the Legacy shop module. A backend editor could perform object injection in discount rules. This would require backend access and permission to edit discount rules. While object injection in itself is a serious vulnerability, the permission requirement means that normally only administrators would be able to exploit it, that's why it was classified as Medium severity. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
+ 12 more Show less
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
Fixed in
5.4.14.2
2017.12.7.3
2019.3.5.1
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-9895-26wr-4fgv
May 15, 2024
EZsystems Remote code execution in file uploads
High
This Security Advisory is about a vulnerability in the way eZ Platform and eZ Publish Legacy handles file uploads, which can in the worst case lead to remote code execution (RCE), a very serious threat. An attacker would need access to uploading files to be able to exploit the vulnerability, so if you have strict controls on this and trust all who have this permission, you're not affected. On the basis of the tests we have made, we also believe the vulnerability cannot be exploited as long as our recommended vhost configuration is used. Here is the v2.5 recommendation for Nginx, as an example: https://github.com/ezsystems/ezplatform/blob/2.5/doc/nginx/vhost.template#L31 This vhost template specifies that only the file app.php in the web root is executed, while vulnerable configurations allow execution of any php file. Apache is affected in the same way as Nginx, and is also protected by using the recommended configuration. The build-in webserver in PHP stays vulnerable, as it doesn't use this type of configuration (this webserver should only be used for development, never for production). We cannot be 100% certain our configuration is not vulnerable. We also do not know if all our users use the recommended configuration, so we send out this fix to be on the safe side. The fix includes a blacklist feature for uploaded filenames, such as ".php". The file types on the blacklist cannot be uploaded. The blacklist is configurable. In eZ Platform you will find it as ezsettings.default.io.file_storage.file_type_blacklist in eZ/Bundle/EzPublishCoreBundle/Resources/config/default_settings.yml in vendors/ezsystems/ezpublish-kernel. In eZ Publish Legacy you will find it as FileExtensionBlackList in settings/file.ini. By default it blocks these file types: php, php3, phar, phpt, pht, phtml, pgif. The fix also inclues a new block against path traversal attacks, though this kind of attack was not reproducible in our tests. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
+ 9 more Show less
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
Fixed in
5.4.14.1
2017.12.7.2
2019.3.4.2
References Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-10806
GHSA-54p5-gxq6-j98g
May 24, 2022
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. Affected versions
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
+ 17 more Show less
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
Fixed in
5.4.14.1
2017.12.7.2
2019.03.4.2
References Updated Dec 08, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2019.03.3
patch
4 CVEs
GHSA-39j2-4p9j-5w4j
May 15, 2024
Ez Platform Object Injection in legacy shop module
Medium
This Security Advisory is about a vulnerability in the Legacy shop module. A backend editor could perform object injection in discount rules. This would require backend access and permission to edit discount rules. While object injection in itself is a serious vulnerability, the permission requirement means that normally only administrators would be able to exploit it, that's why it was classified as Medium severity. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
+ 12 more Show less
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
Fixed in
5.4.14.2
2017.12.7.3
2019.3.5.1
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-9895-26wr-4fgv
May 15, 2024
EZsystems Remote code execution in file uploads
High
This Security Advisory is about a vulnerability in the way eZ Platform and eZ Publish Legacy handles file uploads, which can in the worst case lead to remote code execution (RCE), a very serious threat. An attacker would need access to uploading files to be able to exploit the vulnerability, so if you have strict controls on this and trust all who have this permission, you're not affected. On the basis of the tests we have made, we also believe the vulnerability cannot be exploited as long as our recommended vhost configuration is used. Here is the v2.5 recommendation for Nginx, as an example: https://github.com/ezsystems/ezplatform/blob/2.5/doc/nginx/vhost.template#L31 This vhost template specifies that only the file app.php in the web root is executed, while vulnerable configurations allow execution of any php file. Apache is affected in the same way as Nginx, and is also protected by using the recommended configuration. The build-in webserver in PHP stays vulnerable, as it doesn't use this type of configuration (this webserver should only be used for development, never for production). We cannot be 100% certain our configuration is not vulnerable. We also do not know if all our users use the recommended configuration, so we send out this fix to be on the safe side. The fix includes a blacklist feature for uploaded filenames, such as ".php". The file types on the blacklist cannot be uploaded. The blacklist is configurable. In eZ Platform you will find it as ezsettings.default.io.file_storage.file_type_blacklist in eZ/Bundle/EzPublishCoreBundle/Resources/config/default_settings.yml in vendors/ezsystems/ezpublish-kernel. In eZ Publish Legacy you will find it as FileExtensionBlackList in settings/file.ini. By default it blocks these file types: php, php3, phar, phpt, pht, phtml, pgif. The fix also inclues a new block against path traversal attacks, though this kind of attack was not reproducible in our tests. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
+ 9 more Show less
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
Fixed in
5.4.14.1
2017.12.7.2
2019.3.4.2
References Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-10806
GHSA-54p5-gxq6-j98g
May 24, 2022
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. Affected versions
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
+ 17 more Show less
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
Fixed in
5.4.14.1
2017.12.7.2
2019.03.4.2
References Updated Dec 08, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2019.03.2
patch
4 CVEs
GHSA-39j2-4p9j-5w4j
May 15, 2024
Ez Platform Object Injection in legacy shop module
Medium
This Security Advisory is about a vulnerability in the Legacy shop module. A backend editor could perform object injection in discount rules. This would require backend access and permission to edit discount rules. While object injection in itself is a serious vulnerability, the permission requirement means that normally only administrators would be able to exploit it, that's why it was classified as Medium severity. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
+ 12 more Show less
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
Fixed in
5.4.14.2
2017.12.7.3
2019.3.5.1
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-9895-26wr-4fgv
May 15, 2024
EZsystems Remote code execution in file uploads
High
This Security Advisory is about a vulnerability in the way eZ Platform and eZ Publish Legacy handles file uploads, which can in the worst case lead to remote code execution (RCE), a very serious threat. An attacker would need access to uploading files to be able to exploit the vulnerability, so if you have strict controls on this and trust all who have this permission, you're not affected. On the basis of the tests we have made, we also believe the vulnerability cannot be exploited as long as our recommended vhost configuration is used. Here is the v2.5 recommendation for Nginx, as an example: https://github.com/ezsystems/ezplatform/blob/2.5/doc/nginx/vhost.template#L31 This vhost template specifies that only the file app.php in the web root is executed, while vulnerable configurations allow execution of any php file. Apache is affected in the same way as Nginx, and is also protected by using the recommended configuration. The build-in webserver in PHP stays vulnerable, as it doesn't use this type of configuration (this webserver should only be used for development, never for production). We cannot be 100% certain our configuration is not vulnerable. We also do not know if all our users use the recommended configuration, so we send out this fix to be on the safe side. The fix includes a blacklist feature for uploaded filenames, such as ".php". The file types on the blacklist cannot be uploaded. The blacklist is configurable. In eZ Platform you will find it as ezsettings.default.io.file_storage.file_type_blacklist in eZ/Bundle/EzPublishCoreBundle/Resources/config/default_settings.yml in vendors/ezsystems/ezpublish-kernel. In eZ Publish Legacy you will find it as FileExtensionBlackList in settings/file.ini. By default it blocks these file types: php, php3, phar, phpt, pht, phtml, pgif. The fix also inclues a new block against path traversal attacks, though this kind of attack was not reproducible in our tests. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
+ 9 more Show less
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
Fixed in
5.4.14.1
2017.12.7.2
2019.3.4.2
References Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-10806
GHSA-54p5-gxq6-j98g
May 24, 2022
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. Affected versions
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
+ 17 more Show less
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
Fixed in
5.4.14.1
2017.12.7.2
2019.03.4.2
References Updated Dec 08, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2019.03.1
patch
4 CVEs
GHSA-39j2-4p9j-5w4j
May 15, 2024
Ez Platform Object Injection in legacy shop module
Medium
This Security Advisory is about a vulnerability in the Legacy shop module. A backend editor could perform object injection in discount rules. This would require backend access and permission to edit discount rules. While object injection in itself is a serious vulnerability, the permission requirement means that normally only administrators would be able to exploit it, that's why it was classified as Medium severity. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
+ 12 more Show less
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
Fixed in
5.4.14.2
2017.12.7.3
2019.3.5.1
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-9895-26wr-4fgv
May 15, 2024
EZsystems Remote code execution in file uploads
High
This Security Advisory is about a vulnerability in the way eZ Platform and eZ Publish Legacy handles file uploads, which can in the worst case lead to remote code execution (RCE), a very serious threat. An attacker would need access to uploading files to be able to exploit the vulnerability, so if you have strict controls on this and trust all who have this permission, you're not affected. On the basis of the tests we have made, we also believe the vulnerability cannot be exploited as long as our recommended vhost configuration is used. Here is the v2.5 recommendation for Nginx, as an example: https://github.com/ezsystems/ezplatform/blob/2.5/doc/nginx/vhost.template#L31 This vhost template specifies that only the file app.php in the web root is executed, while vulnerable configurations allow execution of any php file. Apache is affected in the same way as Nginx, and is also protected by using the recommended configuration. The build-in webserver in PHP stays vulnerable, as it doesn't use this type of configuration (this webserver should only be used for development, never for production). We cannot be 100% certain our configuration is not vulnerable. We also do not know if all our users use the recommended configuration, so we send out this fix to be on the safe side. The fix includes a blacklist feature for uploaded filenames, such as ".php". The file types on the blacklist cannot be uploaded. The blacklist is configurable. In eZ Platform you will find it as ezsettings.default.io.file_storage.file_type_blacklist in eZ/Bundle/EzPublishCoreBundle/Resources/config/default_settings.yml in vendors/ezsystems/ezpublish-kernel. In eZ Publish Legacy you will find it as FileExtensionBlackList in settings/file.ini. By default it blocks these file types: php, php3, phar, phpt, pht, phtml, pgif. The fix also inclues a new block against path traversal attacks, though this kind of attack was not reproducible in our tests. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
+ 9 more Show less
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
Fixed in
5.4.14.1
2017.12.7.2
2019.3.4.2
References Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-10806
GHSA-54p5-gxq6-j98g
May 24, 2022
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. Affected versions
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
+ 17 more Show less
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
Fixed in
5.4.14.1
2017.12.7.2
2019.03.4.2
References Updated Dec 08, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2019.03.0
major
4 CVEs
GHSA-39j2-4p9j-5w4j
May 15, 2024
Ez Platform Object Injection in legacy shop module
Medium
This Security Advisory is about a vulnerability in the Legacy shop module. A backend editor could perform object injection in discount rules. This would require backend access and permission to edit discount rules. While object injection in itself is a serious vulnerability, the permission requirement means that normally only administrators would be able to exploit it, that's why it was classified as Medium severity. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
+ 12 more Show less
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
Fixed in
5.4.14.2
2017.12.7.3
2019.3.5.1
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-9895-26wr-4fgv
May 15, 2024
EZsystems Remote code execution in file uploads
High
This Security Advisory is about a vulnerability in the way eZ Platform and eZ Publish Legacy handles file uploads, which can in the worst case lead to remote code execution (RCE), a very serious threat. An attacker would need access to uploading files to be able to exploit the vulnerability, so if you have strict controls on this and trust all who have this permission, you're not affected. On the basis of the tests we have made, we also believe the vulnerability cannot be exploited as long as our recommended vhost configuration is used. Here is the v2.5 recommendation for Nginx, as an example: https://github.com/ezsystems/ezplatform/blob/2.5/doc/nginx/vhost.template#L31 This vhost template specifies that only the file app.php in the web root is executed, while vulnerable configurations allow execution of any php file. Apache is affected in the same way as Nginx, and is also protected by using the recommended configuration. The build-in webserver in PHP stays vulnerable, as it doesn't use this type of configuration (this webserver should only be used for development, never for production). We cannot be 100% certain our configuration is not vulnerable. We also do not know if all our users use the recommended configuration, so we send out this fix to be on the safe side. The fix includes a blacklist feature for uploaded filenames, such as ".php". The file types on the blacklist cannot be uploaded. The blacklist is configurable. In eZ Platform you will find it as ezsettings.default.io.file_storage.file_type_blacklist in eZ/Bundle/EzPublishCoreBundle/Resources/config/default_settings.yml in vendors/ezsystems/ezpublish-kernel. In eZ Publish Legacy you will find it as FileExtensionBlackList in settings/file.ini. By default it blocks these file types: php, php3, phar, phpt, pht, phtml, pgif. The fix also inclues a new block against path traversal attacks, though this kind of attack was not reproducible in our tests. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
+ 9 more Show less
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
Fixed in
5.4.14.1
2017.12.7.2
2019.3.4.2
References Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-10806
GHSA-54p5-gxq6-j98g
May 24, 2022
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. Affected versions
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
+ 17 more Show less
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
Fixed in
5.4.14.1
2017.12.7.2
2019.03.4.2
References Updated Dec 08, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2019.03.0-rc2
pre
2 CVEs
CVE-2020-10806
GHSA-54p5-gxq6-j98g
May 24, 2022
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. Affected versions
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
+ 17 more Show less
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
Fixed in
5.4.14.1
2017.12.7.2
2019.03.4.2
References Updated Dec 08, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2018.09.5
patch
1 CVE
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2017.12.7
patch
4 CVEs
GHSA-39j2-4p9j-5w4j
May 15, 2024
Ez Platform Object Injection in legacy shop module
Medium
This Security Advisory is about a vulnerability in the Legacy shop module. A backend editor could perform object injection in discount rules. This would require backend access and permission to edit discount rules. While object injection in itself is a serious vulnerability, the permission requirement means that normally only administrators would be able to exploit it, that's why it was classified as Medium severity. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
+ 12 more Show less
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
Fixed in
5.4.14.2
2017.12.7.3
2019.3.5.1
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-9895-26wr-4fgv
May 15, 2024
EZsystems Remote code execution in file uploads
High
This Security Advisory is about a vulnerability in the way eZ Platform and eZ Publish Legacy handles file uploads, which can in the worst case lead to remote code execution (RCE), a very serious threat. An attacker would need access to uploading files to be able to exploit the vulnerability, so if you have strict controls on this and trust all who have this permission, you're not affected. On the basis of the tests we have made, we also believe the vulnerability cannot be exploited as long as our recommended vhost configuration is used. Here is the v2.5 recommendation for Nginx, as an example: https://github.com/ezsystems/ezplatform/blob/2.5/doc/nginx/vhost.template#L31 This vhost template specifies that only the file app.php in the web root is executed, while vulnerable configurations allow execution of any php file. Apache is affected in the same way as Nginx, and is also protected by using the recommended configuration. The build-in webserver in PHP stays vulnerable, as it doesn't use this type of configuration (this webserver should only be used for development, never for production). We cannot be 100% certain our configuration is not vulnerable. We also do not know if all our users use the recommended configuration, so we send out this fix to be on the safe side. The fix includes a blacklist feature for uploaded filenames, such as ".php". The file types on the blacklist cannot be uploaded. The blacklist is configurable. In eZ Platform you will find it as ezsettings.default.io.file_storage.file_type_blacklist in eZ/Bundle/EzPublishCoreBundle/Resources/config/default_settings.yml in vendors/ezsystems/ezpublish-kernel. In eZ Publish Legacy you will find it as FileExtensionBlackList in settings/file.ini. By default it blocks these file types: php, php3, phar, phpt, pht, phtml, pgif. The fix also inclues a new block against path traversal attacks, though this kind of attack was not reproducible in our tests. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
+ 9 more Show less
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
Fixed in
5.4.14.1
2017.12.7.2
2019.3.4.2
References Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-10806
GHSA-54p5-gxq6-j98g
May 24, 2022
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. Affected versions
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
+ 17 more Show less
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
Fixed in
5.4.14.1
2017.12.7.2
2019.03.4.2
References Updated Dec 08, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2019.03.0-rc1
pre
2 CVEs
CVE-2020-10806
GHSA-54p5-gxq6-j98g
May 24, 2022
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. Affected versions
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
+ 17 more Show less
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
Fixed in
5.4.14.1
2017.12.7.2
2019.03.4.2
References Updated Dec 08, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2018.09.4
patch
1 CVE
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2017.12.6
patch
4 CVEs
GHSA-39j2-4p9j-5w4j
May 15, 2024
Ez Platform Object Injection in legacy shop module
Medium
This Security Advisory is about a vulnerability in the Legacy shop module. A backend editor could perform object injection in discount rules. This would require backend access and permission to edit discount rules. While object injection in itself is a serious vulnerability, the permission requirement means that normally only administrators would be able to exploit it, that's why it was classified as Medium severity. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
+ 12 more Show less
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
Fixed in
5.4.14.2
2017.12.7.3
2019.3.5.1
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-9895-26wr-4fgv
May 15, 2024
EZsystems Remote code execution in file uploads
High
This Security Advisory is about a vulnerability in the way eZ Platform and eZ Publish Legacy handles file uploads, which can in the worst case lead to remote code execution (RCE), a very serious threat. An attacker would need access to uploading files to be able to exploit the vulnerability, so if you have strict controls on this and trust all who have this permission, you're not affected. On the basis of the tests we have made, we also believe the vulnerability cannot be exploited as long as our recommended vhost configuration is used. Here is the v2.5 recommendation for Nginx, as an example: https://github.com/ezsystems/ezplatform/blob/2.5/doc/nginx/vhost.template#L31 This vhost template specifies that only the file app.php in the web root is executed, while vulnerable configurations allow execution of any php file. Apache is affected in the same way as Nginx, and is also protected by using the recommended configuration. The build-in webserver in PHP stays vulnerable, as it doesn't use this type of configuration (this webserver should only be used for development, never for production). We cannot be 100% certain our configuration is not vulnerable. We also do not know if all our users use the recommended configuration, so we send out this fix to be on the safe side. The fix includes a blacklist feature for uploaded filenames, such as ".php". The file types on the blacklist cannot be uploaded. The blacklist is configurable. In eZ Platform you will find it as ezsettings.default.io.file_storage.file_type_blacklist in eZ/Bundle/EzPublishCoreBundle/Resources/config/default_settings.yml in vendors/ezsystems/ezpublish-kernel. In eZ Publish Legacy you will find it as FileExtensionBlackList in settings/file.ini. By default it blocks these file types: php, php3, phar, phpt, pht, phtml, pgif. The fix also inclues a new block against path traversal attacks, though this kind of attack was not reproducible in our tests. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
+ 9 more Show less
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
Fixed in
5.4.14.1
2017.12.7.2
2019.3.4.2
References Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-10806
GHSA-54p5-gxq6-j98g
May 24, 2022
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. Affected versions
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
+ 17 more Show less
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
Fixed in
5.4.14.1
2017.12.7.2
2019.03.4.2
References Updated Dec 08, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2018.09.3
patch
1 CVE
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2017.12.5
patch
4 CVEs
GHSA-39j2-4p9j-5w4j
May 15, 2024
Ez Platform Object Injection in legacy shop module
Medium
This Security Advisory is about a vulnerability in the Legacy shop module. A backend editor could perform object injection in discount rules. This would require backend access and permission to edit discount rules. While object injection in itself is a serious vulnerability, the permission requirement means that normally only administrators would be able to exploit it, that's why it was classified as Medium severity. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
+ 12 more Show less
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
Fixed in
5.4.14.2
2017.12.7.3
2019.3.5.1
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-9895-26wr-4fgv
May 15, 2024
EZsystems Remote code execution in file uploads
High
This Security Advisory is about a vulnerability in the way eZ Platform and eZ Publish Legacy handles file uploads, which can in the worst case lead to remote code execution (RCE), a very serious threat. An attacker would need access to uploading files to be able to exploit the vulnerability, so if you have strict controls on this and trust all who have this permission, you're not affected. On the basis of the tests we have made, we also believe the vulnerability cannot be exploited as long as our recommended vhost configuration is used. Here is the v2.5 recommendation for Nginx, as an example: https://github.com/ezsystems/ezplatform/blob/2.5/doc/nginx/vhost.template#L31 This vhost template specifies that only the file app.php in the web root is executed, while vulnerable configurations allow execution of any php file. Apache is affected in the same way as Nginx, and is also protected by using the recommended configuration. The build-in webserver in PHP stays vulnerable, as it doesn't use this type of configuration (this webserver should only be used for development, never for production). We cannot be 100% certain our configuration is not vulnerable. We also do not know if all our users use the recommended configuration, so we send out this fix to be on the safe side. The fix includes a blacklist feature for uploaded filenames, such as ".php". The file types on the blacklist cannot be uploaded. The blacklist is configurable. In eZ Platform you will find it as ezsettings.default.io.file_storage.file_type_blacklist in eZ/Bundle/EzPublishCoreBundle/Resources/config/default_settings.yml in vendors/ezsystems/ezpublish-kernel. In eZ Publish Legacy you will find it as FileExtensionBlackList in settings/file.ini. By default it blocks these file types: php, php3, phar, phpt, pht, phtml, pgif. The fix also inclues a new block against path traversal attacks, though this kind of attack was not reproducible in our tests. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
+ 9 more Show less
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
Fixed in
5.4.14.1
2017.12.7.2
2019.3.4.2
References Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-10806
GHSA-54p5-gxq6-j98g
May 24, 2022
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. Affected versions
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
+ 17 more Show less
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
Fixed in
5.4.14.1
2017.12.7.2
2019.03.4.2
References Updated Dec 08, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2018.09.2
patch
1 CVE
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2018.09.1.3
patch
1 CVE
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2017.12.4.3
patch
4 CVEs
GHSA-39j2-4p9j-5w4j
May 15, 2024
Ez Platform Object Injection in legacy shop module
Medium
This Security Advisory is about a vulnerability in the Legacy shop module. A backend editor could perform object injection in discount rules. This would require backend access and permission to edit discount rules. While object injection in itself is a serious vulnerability, the permission requirement means that normally only administrators would be able to exploit it, that's why it was classified as Medium severity. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
+ 12 more Show less
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
Fixed in
5.4.14.2
2017.12.7.3
2019.3.5.1
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-9895-26wr-4fgv
May 15, 2024
EZsystems Remote code execution in file uploads
High
This Security Advisory is about a vulnerability in the way eZ Platform and eZ Publish Legacy handles file uploads, which can in the worst case lead to remote code execution (RCE), a very serious threat. An attacker would need access to uploading files to be able to exploit the vulnerability, so if you have strict controls on this and trust all who have this permission, you're not affected. On the basis of the tests we have made, we also believe the vulnerability cannot be exploited as long as our recommended vhost configuration is used. Here is the v2.5 recommendation for Nginx, as an example: https://github.com/ezsystems/ezplatform/blob/2.5/doc/nginx/vhost.template#L31 This vhost template specifies that only the file app.php in the web root is executed, while vulnerable configurations allow execution of any php file. Apache is affected in the same way as Nginx, and is also protected by using the recommended configuration. The build-in webserver in PHP stays vulnerable, as it doesn't use this type of configuration (this webserver should only be used for development, never for production). We cannot be 100% certain our configuration is not vulnerable. We also do not know if all our users use the recommended configuration, so we send out this fix to be on the safe side. The fix includes a blacklist feature for uploaded filenames, such as ".php". The file types on the blacklist cannot be uploaded. The blacklist is configurable. In eZ Platform you will find it as ezsettings.default.io.file_storage.file_type_blacklist in eZ/Bundle/EzPublishCoreBundle/Resources/config/default_settings.yml in vendors/ezsystems/ezpublish-kernel. In eZ Publish Legacy you will find it as FileExtensionBlackList in settings/file.ini. By default it blocks these file types: php, php3, phar, phpt, pht, phtml, pgif. The fix also inclues a new block against path traversal attacks, though this kind of attack was not reproducible in our tests. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
+ 9 more Show less
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
Fixed in
5.4.14.1
2017.12.7.2
2019.3.4.2
References Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-10806
GHSA-54p5-gxq6-j98g
May 24, 2022
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. Affected versions
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
+ 17 more Show less
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
Fixed in
5.4.14.1
2017.12.7.2
2019.03.4.2
References Updated Dec 08, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2018.06.1.3
patch
2 CVEs
GHSA-pqjm-xcp8-wgmm
May 15, 2024
Ez Platform and Legacy are prone to an insecure interpretation of PHP/PHAR uploads
Medium
The eZ Platform and Legacy are affected by an issue related to how uploaded PHP and PHAR files are handled, and consists of two parts: 1. Web server configuration, and 2. Disabling the PHAR stream wrapper. 1. WEB SERVER CONFIGURATION The sample web server configuration in our documentation can in some cases allow the execution of uploaded PHP/PHAR code. This can be abused to allow priviledge escalation and breach of content access controls, among other things. Please ensure that your web server will not execute files in directories were files may be uploaded, such as web/var/ and ezpublish_legacy/var/ As an example, here is how you can make Apache return HTTP 403 Forbidden for a number of executable file types in your eZ Platform var directory. Please adapt it to your needs. It is then possible to enable logging of HTTP 403 in a separate log file if you wish, you could do this to see if someone is trying to abuse the server.
Here is the same configuration, but for the Nginx web server:
2. DISABLE PHAR STREAM WRAPPER PHAR archives may be crafted such that its stream wrapper will execute them without being specifically asked to. With such files, any PHP file operation may cause deserialisation and execution. This may happen even if the file name suffix isn't ".phar". Any site that allows file uploads is at risk. Normally eZ Platform has no need for PHAR support. It's only used by Composer, and that is executed separately from eZ Platform. So one way to avoid this vulnerability is to disable the PHAR stream wrapper within eZ Platform. (If you know you need PHAR support, please consider other means to deal with this vulnerability. For example, enabling the wrapper only in those scripts/bundles that have to deal with such files.) Disabling the stream wrapper should be done in: eZ Platform (web/app.php) CLI scripts (bin/console) Legacy (index.php and CLI scripts) To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezplatform/commit/9a0c52dc4535e4b3ce379f80222dc53f705a2cfd https://github.com/ezsystems/ezpublish-legacy/commit/d21957bf202b091ab39dfb5be300f6c30be3933e Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
2013.04.0
v2013.05.0
v2013.06.0
+ 41 more Show less
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
Fixed in
5.3.12.6
5.4.12.3
2017.12.4.3
2018.6.1.4
2018.9.1.3
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2018.09.1.2
patch
2 CVEs
GHSA-pqjm-xcp8-wgmm
May 15, 2024
Ez Platform and Legacy are prone to an insecure interpretation of PHP/PHAR uploads
Medium
The eZ Platform and Legacy are affected by an issue related to how uploaded PHP and PHAR files are handled, and consists of two parts: 1. Web server configuration, and 2. Disabling the PHAR stream wrapper. 1. WEB SERVER CONFIGURATION The sample web server configuration in our documentation can in some cases allow the execution of uploaded PHP/PHAR code. This can be abused to allow priviledge escalation and breach of content access controls, among other things. Please ensure that your web server will not execute files in directories were files may be uploaded, such as web/var/ and ezpublish_legacy/var/ As an example, here is how you can make Apache return HTTP 403 Forbidden for a number of executable file types in your eZ Platform var directory. Please adapt it to your needs. It is then possible to enable logging of HTTP 403 in a separate log file if you wish, you could do this to see if someone is trying to abuse the server.
Here is the same configuration, but for the Nginx web server:
2. DISABLE PHAR STREAM WRAPPER PHAR archives may be crafted such that its stream wrapper will execute them without being specifically asked to. With such files, any PHP file operation may cause deserialisation and execution. This may happen even if the file name suffix isn't ".phar". Any site that allows file uploads is at risk. Normally eZ Platform has no need for PHAR support. It's only used by Composer, and that is executed separately from eZ Platform. So one way to avoid this vulnerability is to disable the PHAR stream wrapper within eZ Platform. (If you know you need PHAR support, please consider other means to deal with this vulnerability. For example, enabling the wrapper only in those scripts/bundles that have to deal with such files.) Disabling the stream wrapper should be done in: eZ Platform (web/app.php) CLI scripts (bin/console) Legacy (index.php and CLI scripts) To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezplatform/commit/9a0c52dc4535e4b3ce379f80222dc53f705a2cfd https://github.com/ezsystems/ezpublish-legacy/commit/d21957bf202b091ab39dfb5be300f6c30be3933e Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
2013.04.0
v2013.05.0
v2013.06.0
+ 41 more Show less
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
Fixed in
5.3.12.6
5.4.12.3
2017.12.4.3
2018.6.1.4
2018.9.1.3
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2017.12.4.2
patch
5 CVEs
GHSA-39j2-4p9j-5w4j
May 15, 2024
Ez Platform Object Injection in legacy shop module
Medium
This Security Advisory is about a vulnerability in the Legacy shop module. A backend editor could perform object injection in discount rules. This would require backend access and permission to edit discount rules. While object injection in itself is a serious vulnerability, the permission requirement means that normally only administrators would be able to exploit it, that's why it was classified as Medium severity. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
+ 12 more Show less
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
Fixed in
5.4.14.2
2017.12.7.3
2019.3.5.1
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-9895-26wr-4fgv
May 15, 2024
EZsystems Remote code execution in file uploads
High
This Security Advisory is about a vulnerability in the way eZ Platform and eZ Publish Legacy handles file uploads, which can in the worst case lead to remote code execution (RCE), a very serious threat. An attacker would need access to uploading files to be able to exploit the vulnerability, so if you have strict controls on this and trust all who have this permission, you're not affected. On the basis of the tests we have made, we also believe the vulnerability cannot be exploited as long as our recommended vhost configuration is used. Here is the v2.5 recommendation for Nginx, as an example: https://github.com/ezsystems/ezplatform/blob/2.5/doc/nginx/vhost.template#L31 This vhost template specifies that only the file app.php in the web root is executed, while vulnerable configurations allow execution of any php file. Apache is affected in the same way as Nginx, and is also protected by using the recommended configuration. The build-in webserver in PHP stays vulnerable, as it doesn't use this type of configuration (this webserver should only be used for development, never for production). We cannot be 100% certain our configuration is not vulnerable. We also do not know if all our users use the recommended configuration, so we send out this fix to be on the safe side. The fix includes a blacklist feature for uploaded filenames, such as ".php". The file types on the blacklist cannot be uploaded. The blacklist is configurable. In eZ Platform you will find it as ezsettings.default.io.file_storage.file_type_blacklist in eZ/Bundle/EzPublishCoreBundle/Resources/config/default_settings.yml in vendors/ezsystems/ezpublish-kernel. In eZ Publish Legacy you will find it as FileExtensionBlackList in settings/file.ini. By default it blocks these file types: php, php3, phar, phpt, pht, phtml, pgif. The fix also inclues a new block against path traversal attacks, though this kind of attack was not reproducible in our tests. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
+ 9 more Show less
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
Fixed in
5.4.14.1
2017.12.7.2
2019.3.4.2
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-pqjm-xcp8-wgmm
May 15, 2024
Ez Platform and Legacy are prone to an insecure interpretation of PHP/PHAR uploads
Medium
The eZ Platform and Legacy are affected by an issue related to how uploaded PHP and PHAR files are handled, and consists of two parts: 1. Web server configuration, and 2. Disabling the PHAR stream wrapper. 1. WEB SERVER CONFIGURATION The sample web server configuration in our documentation can in some cases allow the execution of uploaded PHP/PHAR code. This can be abused to allow priviledge escalation and breach of content access controls, among other things. Please ensure that your web server will not execute files in directories were files may be uploaded, such as web/var/ and ezpublish_legacy/var/ As an example, here is how you can make Apache return HTTP 403 Forbidden for a number of executable file types in your eZ Platform var directory. Please adapt it to your needs. It is then possible to enable logging of HTTP 403 in a separate log file if you wish, you could do this to see if someone is trying to abuse the server.
Here is the same configuration, but for the Nginx web server:
2. DISABLE PHAR STREAM WRAPPER PHAR archives may be crafted such that its stream wrapper will execute them without being specifically asked to. With such files, any PHP file operation may cause deserialisation and execution. This may happen even if the file name suffix isn't ".phar". Any site that allows file uploads is at risk. Normally eZ Platform has no need for PHAR support. It's only used by Composer, and that is executed separately from eZ Platform. So one way to avoid this vulnerability is to disable the PHAR stream wrapper within eZ Platform. (If you know you need PHAR support, please consider other means to deal with this vulnerability. For example, enabling the wrapper only in those scripts/bundles that have to deal with such files.) Disabling the stream wrapper should be done in: eZ Platform (web/app.php) CLI scripts (bin/console) Legacy (index.php and CLI scripts) To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezplatform/commit/9a0c52dc4535e4b3ce379f80222dc53f705a2cfd https://github.com/ezsystems/ezpublish-legacy/commit/d21957bf202b091ab39dfb5be300f6c30be3933e Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
2013.04.0
v2013.05.0
v2013.06.0
+ 41 more Show less
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
Fixed in
5.3.12.6
5.4.12.3
2017.12.4.3
2018.6.1.4
2018.9.1.3
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-10806
GHSA-54p5-gxq6-j98g
May 24, 2022
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. Affected versions
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
+ 17 more Show less
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
Fixed in
5.4.14.1
2017.12.7.2
2019.03.4.2
References Updated Dec 08, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2018.06.1.2
patch
3 CVEs
GHSA-pqjm-xcp8-wgmm
May 15, 2024
Ez Platform and Legacy are prone to an insecure interpretation of PHP/PHAR uploads
Medium
The eZ Platform and Legacy are affected by an issue related to how uploaded PHP and PHAR files are handled, and consists of two parts: 1. Web server configuration, and 2. Disabling the PHAR stream wrapper. 1. WEB SERVER CONFIGURATION The sample web server configuration in our documentation can in some cases allow the execution of uploaded PHP/PHAR code. This can be abused to allow priviledge escalation and breach of content access controls, among other things. Please ensure that your web server will not execute files in directories were files may be uploaded, such as web/var/ and ezpublish_legacy/var/ As an example, here is how you can make Apache return HTTP 403 Forbidden for a number of executable file types in your eZ Platform var directory. Please adapt it to your needs. It is then possible to enable logging of HTTP 403 in a separate log file if you wish, you could do this to see if someone is trying to abuse the server.
Here is the same configuration, but for the Nginx web server:
2. DISABLE PHAR STREAM WRAPPER PHAR archives may be crafted such that its stream wrapper will execute them without being specifically asked to. With such files, any PHP file operation may cause deserialisation and execution. This may happen even if the file name suffix isn't ".phar". Any site that allows file uploads is at risk. Normally eZ Platform has no need for PHAR support. It's only used by Composer, and that is executed separately from eZ Platform. So one way to avoid this vulnerability is to disable the PHAR stream wrapper within eZ Platform. (If you know you need PHAR support, please consider other means to deal with this vulnerability. For example, enabling the wrapper only in those scripts/bundles that have to deal with such files.) Disabling the stream wrapper should be done in: eZ Platform (web/app.php) CLI scripts (bin/console) Legacy (index.php and CLI scripts) To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezplatform/commit/9a0c52dc4535e4b3ce379f80222dc53f705a2cfd https://github.com/ezsystems/ezpublish-legacy/commit/d21957bf202b091ab39dfb5be300f6c30be3933e Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
2013.04.0
v2013.05.0
v2013.06.0
+ 41 more Show less
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
Fixed in
5.3.12.6
5.4.12.3
2017.12.4.3
2018.6.1.4
2018.9.1.3
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-2vh3-cj9j-mcj5
May 15, 2024
eZ Publish Legacy Cross-site Scripting (XSS) in 'disabled module' error template
Medium
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy via the LegacyBridge. Installations where all modules are disabled may be vulnerable to XSS injection in the module name. This is a rare configuration, but we still recommend installing the update, which adds the necessary input washing. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/4697bff700e8cf95d5847ea19dad3479a77b02d9 Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
+ 38 more Show less
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
Fixed in
5.3.12.5
5.4.12.2
2017.12.4.2
2018.6.1.3
2018.9.1.2
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2018.09.1.1
patch
3 CVEs
GHSA-pqjm-xcp8-wgmm
May 15, 2024
Ez Platform and Legacy are prone to an insecure interpretation of PHP/PHAR uploads
Medium
The eZ Platform and Legacy are affected by an issue related to how uploaded PHP and PHAR files are handled, and consists of two parts: 1. Web server configuration, and 2. Disabling the PHAR stream wrapper. 1. WEB SERVER CONFIGURATION The sample web server configuration in our documentation can in some cases allow the execution of uploaded PHP/PHAR code. This can be abused to allow priviledge escalation and breach of content access controls, among other things. Please ensure that your web server will not execute files in directories were files may be uploaded, such as web/var/ and ezpublish_legacy/var/ As an example, here is how you can make Apache return HTTP 403 Forbidden for a number of executable file types in your eZ Platform var directory. Please adapt it to your needs. It is then possible to enable logging of HTTP 403 in a separate log file if you wish, you could do this to see if someone is trying to abuse the server.
Here is the same configuration, but for the Nginx web server:
2. DISABLE PHAR STREAM WRAPPER PHAR archives may be crafted such that its stream wrapper will execute them without being specifically asked to. With such files, any PHP file operation may cause deserialisation and execution. This may happen even if the file name suffix isn't ".phar". Any site that allows file uploads is at risk. Normally eZ Platform has no need for PHAR support. It's only used by Composer, and that is executed separately from eZ Platform. So one way to avoid this vulnerability is to disable the PHAR stream wrapper within eZ Platform. (If you know you need PHAR support, please consider other means to deal with this vulnerability. For example, enabling the wrapper only in those scripts/bundles that have to deal with such files.) Disabling the stream wrapper should be done in: eZ Platform (web/app.php) CLI scripts (bin/console) Legacy (index.php and CLI scripts) To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezplatform/commit/9a0c52dc4535e4b3ce379f80222dc53f705a2cfd https://github.com/ezsystems/ezpublish-legacy/commit/d21957bf202b091ab39dfb5be300f6c30be3933e Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
2013.04.0
v2013.05.0
v2013.06.0
+ 41 more Show less
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
Fixed in
5.3.12.6
5.4.12.3
2017.12.4.3
2018.6.1.4
2018.9.1.3
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-2vh3-cj9j-mcj5
May 15, 2024
eZ Publish Legacy Cross-site Scripting (XSS) in 'disabled module' error template
Medium
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy via the LegacyBridge. Installations where all modules are disabled may be vulnerable to XSS injection in the module name. This is a rare configuration, but we still recommend installing the update, which adds the necessary input washing. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/4697bff700e8cf95d5847ea19dad3479a77b02d9 Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
+ 38 more Show less
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
Fixed in
5.3.12.5
5.4.12.2
2017.12.4.2
2018.6.1.3
2018.9.1.2
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2017.12.4.1
patch
6 CVEs
GHSA-39j2-4p9j-5w4j
May 15, 2024
Ez Platform Object Injection in legacy shop module
Medium
This Security Advisory is about a vulnerability in the Legacy shop module. A backend editor could perform object injection in discount rules. This would require backend access and permission to edit discount rules. While object injection in itself is a serious vulnerability, the permission requirement means that normally only administrators would be able to exploit it, that's why it was classified as Medium severity. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
+ 12 more Show less
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
Fixed in
5.4.14.2
2017.12.7.3
2019.3.5.1
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-9895-26wr-4fgv
May 15, 2024
EZsystems Remote code execution in file uploads
High
This Security Advisory is about a vulnerability in the way eZ Platform and eZ Publish Legacy handles file uploads, which can in the worst case lead to remote code execution (RCE), a very serious threat. An attacker would need access to uploading files to be able to exploit the vulnerability, so if you have strict controls on this and trust all who have this permission, you're not affected. On the basis of the tests we have made, we also believe the vulnerability cannot be exploited as long as our recommended vhost configuration is used. Here is the v2.5 recommendation for Nginx, as an example: https://github.com/ezsystems/ezplatform/blob/2.5/doc/nginx/vhost.template#L31 This vhost template specifies that only the file app.php in the web root is executed, while vulnerable configurations allow execution of any php file. Apache is affected in the same way as Nginx, and is also protected by using the recommended configuration. The build-in webserver in PHP stays vulnerable, as it doesn't use this type of configuration (this webserver should only be used for development, never for production). We cannot be 100% certain our configuration is not vulnerable. We also do not know if all our users use the recommended configuration, so we send out this fix to be on the safe side. The fix includes a blacklist feature for uploaded filenames, such as ".php". The file types on the blacklist cannot be uploaded. The blacklist is configurable. In eZ Platform you will find it as ezsettings.default.io.file_storage.file_type_blacklist in eZ/Bundle/EzPublishCoreBundle/Resources/config/default_settings.yml in vendors/ezsystems/ezpublish-kernel. In eZ Publish Legacy you will find it as FileExtensionBlackList in settings/file.ini. By default it blocks these file types: php, php3, phar, phpt, pht, phtml, pgif. The fix also inclues a new block against path traversal attacks, though this kind of attack was not reproducible in our tests. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
+ 9 more Show less
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
Fixed in
5.4.14.1
2017.12.7.2
2019.3.4.2
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-pqjm-xcp8-wgmm
May 15, 2024
Ez Platform and Legacy are prone to an insecure interpretation of PHP/PHAR uploads
Medium
The eZ Platform and Legacy are affected by an issue related to how uploaded PHP and PHAR files are handled, and consists of two parts: 1. Web server configuration, and 2. Disabling the PHAR stream wrapper. 1. WEB SERVER CONFIGURATION The sample web server configuration in our documentation can in some cases allow the execution of uploaded PHP/PHAR code. This can be abused to allow priviledge escalation and breach of content access controls, among other things. Please ensure that your web server will not execute files in directories were files may be uploaded, such as web/var/ and ezpublish_legacy/var/ As an example, here is how you can make Apache return HTTP 403 Forbidden for a number of executable file types in your eZ Platform var directory. Please adapt it to your needs. It is then possible to enable logging of HTTP 403 in a separate log file if you wish, you could do this to see if someone is trying to abuse the server.
Here is the same configuration, but for the Nginx web server:
2. DISABLE PHAR STREAM WRAPPER PHAR archives may be crafted such that its stream wrapper will execute them without being specifically asked to. With such files, any PHP file operation may cause deserialisation and execution. This may happen even if the file name suffix isn't ".phar". Any site that allows file uploads is at risk. Normally eZ Platform has no need for PHAR support. It's only used by Composer, and that is executed separately from eZ Platform. So one way to avoid this vulnerability is to disable the PHAR stream wrapper within eZ Platform. (If you know you need PHAR support, please consider other means to deal with this vulnerability. For example, enabling the wrapper only in those scripts/bundles that have to deal with such files.) Disabling the stream wrapper should be done in: eZ Platform (web/app.php) CLI scripts (bin/console) Legacy (index.php and CLI scripts) To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezplatform/commit/9a0c52dc4535e4b3ce379f80222dc53f705a2cfd https://github.com/ezsystems/ezpublish-legacy/commit/d21957bf202b091ab39dfb5be300f6c30be3933e Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
2013.04.0
v2013.05.0
v2013.06.0
+ 41 more Show less
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
Fixed in
5.3.12.6
5.4.12.3
2017.12.4.3
2018.6.1.4
2018.9.1.3
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-2vh3-cj9j-mcj5
May 15, 2024
eZ Publish Legacy Cross-site Scripting (XSS) in 'disabled module' error template
Medium
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy via the LegacyBridge. Installations where all modules are disabled may be vulnerable to XSS injection in the module name. This is a rare configuration, but we still recommend installing the update, which adds the necessary input washing. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/4697bff700e8cf95d5847ea19dad3479a77b02d9 Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
+ 38 more Show less
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
Fixed in
5.3.12.5
5.4.12.2
2017.12.4.2
2018.6.1.3
2018.9.1.2
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-10806
GHSA-54p5-gxq6-j98g
May 24, 2022
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. Affected versions
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
+ 17 more Show less
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
Fixed in
5.4.14.1
2017.12.7.2
2019.03.4.2
References Updated Dec 08, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2018.06.1.4
patch
1 CVE
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev |
v2018.06.1.4
patch
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
v2018.09.1
patch
4 CVEs
GHSA-pqjm-xcp8-wgmm
May 15, 2024
Ez Platform and Legacy are prone to an insecure interpretation of PHP/PHAR uploads
Medium
The eZ Platform and Legacy are affected by an issue related to how uploaded PHP and PHAR files are handled, and consists of two parts: 1. Web server configuration, and 2. Disabling the PHAR stream wrapper. 1. WEB SERVER CONFIGURATION The sample web server configuration in our documentation can in some cases allow the execution of uploaded PHP/PHAR code. This can be abused to allow priviledge escalation and breach of content access controls, among other things. Please ensure that your web server will not execute files in directories were files may be uploaded, such as web/var/ and ezpublish_legacy/var/ As an example, here is how you can make Apache return HTTP 403 Forbidden for a number of executable file types in your eZ Platform var directory. Please adapt it to your needs. It is then possible to enable logging of HTTP 403 in a separate log file if you wish, you could do this to see if someone is trying to abuse the server.
Here is the same configuration, but for the Nginx web server:
2. DISABLE PHAR STREAM WRAPPER PHAR archives may be crafted such that its stream wrapper will execute them without being specifically asked to. With such files, any PHP file operation may cause deserialisation and execution. This may happen even if the file name suffix isn't ".phar". Any site that allows file uploads is at risk. Normally eZ Platform has no need for PHAR support. It's only used by Composer, and that is executed separately from eZ Platform. So one way to avoid this vulnerability is to disable the PHAR stream wrapper within eZ Platform. (If you know you need PHAR support, please consider other means to deal with this vulnerability. For example, enabling the wrapper only in those scripts/bundles that have to deal with such files.) Disabling the stream wrapper should be done in: eZ Platform (web/app.php) CLI scripts (bin/console) Legacy (index.php and CLI scripts) To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezplatform/commit/9a0c52dc4535e4b3ce379f80222dc53f705a2cfd https://github.com/ezsystems/ezpublish-legacy/commit/d21957bf202b091ab39dfb5be300f6c30be3933e Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
2013.04.0
v2013.05.0
v2013.06.0
+ 41 more Show less
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
Fixed in
5.3.12.6
5.4.12.3
2017.12.4.3
2018.6.1.4
2018.9.1.3
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-p9mp-vq4v-v5m5
May 15, 2024
eZ Publish Legacy Passwordless login for LDAP users
High
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy. Installations that are using the legacy LDAP login handler or the TextFile login handler in combination with the standard legacy login handler, may in rare cases be vulnerable to a failure of the standard login handler to verify passwords correctly, allowing unauthorised access. If your installation has never used the LDAP or TextFile login handlers, or never used legacy login at all, then it is not affected. Still, we recommend installing the update, to be on the safe side. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/13f03a2be6c0ee4d0caaafaef05904ea9b0c4d9d Affected versions
v2018.09.0
v2018.09.1
v2018.06.0
v2018.06.1
v2018.06.1.1
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
+ 35 more Show less
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
Fixed in
5.3.12.4
5.4.12.1
2017.12.4.1
2018.6.1.2
2018.9.1.1
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-2vh3-cj9j-mcj5
May 15, 2024
eZ Publish Legacy Cross-site Scripting (XSS) in 'disabled module' error template
Medium
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy via the LegacyBridge. Installations where all modules are disabled may be vulnerable to XSS injection in the module name. This is a rare configuration, but we still recommend installing the update, which adds the necessary input washing. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/4697bff700e8cf95d5847ea19dad3479a77b02d9 Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
+ 38 more Show less
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
Fixed in
5.3.12.5
5.4.12.2
2017.12.4.2
2018.6.1.3
2018.9.1.2
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2017.12.4
patch
7 CVEs
GHSA-39j2-4p9j-5w4j
May 15, 2024
Ez Platform Object Injection in legacy shop module
Medium
This Security Advisory is about a vulnerability in the Legacy shop module. A backend editor could perform object injection in discount rules. This would require backend access and permission to edit discount rules. While object injection in itself is a serious vulnerability, the permission requirement means that normally only administrators would be able to exploit it, that's why it was classified as Medium severity. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
+ 12 more Show less
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
Fixed in
5.4.14.2
2017.12.7.3
2019.3.5.1
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-9895-26wr-4fgv
May 15, 2024
EZsystems Remote code execution in file uploads
High
This Security Advisory is about a vulnerability in the way eZ Platform and eZ Publish Legacy handles file uploads, which can in the worst case lead to remote code execution (RCE), a very serious threat. An attacker would need access to uploading files to be able to exploit the vulnerability, so if you have strict controls on this and trust all who have this permission, you're not affected. On the basis of the tests we have made, we also believe the vulnerability cannot be exploited as long as our recommended vhost configuration is used. Here is the v2.5 recommendation for Nginx, as an example: https://github.com/ezsystems/ezplatform/blob/2.5/doc/nginx/vhost.template#L31 This vhost template specifies that only the file app.php in the web root is executed, while vulnerable configurations allow execution of any php file. Apache is affected in the same way as Nginx, and is also protected by using the recommended configuration. The build-in webserver in PHP stays vulnerable, as it doesn't use this type of configuration (this webserver should only be used for development, never for production). We cannot be 100% certain our configuration is not vulnerable. We also do not know if all our users use the recommended configuration, so we send out this fix to be on the safe side. The fix includes a blacklist feature for uploaded filenames, such as ".php". The file types on the blacklist cannot be uploaded. The blacklist is configurable. In eZ Platform you will find it as ezsettings.default.io.file_storage.file_type_blacklist in eZ/Bundle/EzPublishCoreBundle/Resources/config/default_settings.yml in vendors/ezsystems/ezpublish-kernel. In eZ Publish Legacy you will find it as FileExtensionBlackList in settings/file.ini. By default it blocks these file types: php, php3, phar, phpt, pht, phtml, pgif. The fix also inclues a new block against path traversal attacks, though this kind of attack was not reproducible in our tests. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
+ 9 more Show less
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
Fixed in
5.4.14.1
2017.12.7.2
2019.3.4.2
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-pqjm-xcp8-wgmm
May 15, 2024
Ez Platform and Legacy are prone to an insecure interpretation of PHP/PHAR uploads
Medium
The eZ Platform and Legacy are affected by an issue related to how uploaded PHP and PHAR files are handled, and consists of two parts: 1. Web server configuration, and 2. Disabling the PHAR stream wrapper. 1. WEB SERVER CONFIGURATION The sample web server configuration in our documentation can in some cases allow the execution of uploaded PHP/PHAR code. This can be abused to allow priviledge escalation and breach of content access controls, among other things. Please ensure that your web server will not execute files in directories were files may be uploaded, such as web/var/ and ezpublish_legacy/var/ As an example, here is how you can make Apache return HTTP 403 Forbidden for a number of executable file types in your eZ Platform var directory. Please adapt it to your needs. It is then possible to enable logging of HTTP 403 in a separate log file if you wish, you could do this to see if someone is trying to abuse the server.
Here is the same configuration, but for the Nginx web server:
2. DISABLE PHAR STREAM WRAPPER PHAR archives may be crafted such that its stream wrapper will execute them without being specifically asked to. With such files, any PHP file operation may cause deserialisation and execution. This may happen even if the file name suffix isn't ".phar". Any site that allows file uploads is at risk. Normally eZ Platform has no need for PHAR support. It's only used by Composer, and that is executed separately from eZ Platform. So one way to avoid this vulnerability is to disable the PHAR stream wrapper within eZ Platform. (If you know you need PHAR support, please consider other means to deal with this vulnerability. For example, enabling the wrapper only in those scripts/bundles that have to deal with such files.) Disabling the stream wrapper should be done in: eZ Platform (web/app.php) CLI scripts (bin/console) Legacy (index.php and CLI scripts) To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezplatform/commit/9a0c52dc4535e4b3ce379f80222dc53f705a2cfd https://github.com/ezsystems/ezpublish-legacy/commit/d21957bf202b091ab39dfb5be300f6c30be3933e Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
2013.04.0
v2013.05.0
v2013.06.0
+ 41 more Show less
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
Fixed in
5.3.12.6
5.4.12.3
2017.12.4.3
2018.6.1.4
2018.9.1.3
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-p9mp-vq4v-v5m5
May 15, 2024
eZ Publish Legacy Passwordless login for LDAP users
High
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy. Installations that are using the legacy LDAP login handler or the TextFile login handler in combination with the standard legacy login handler, may in rare cases be vulnerable to a failure of the standard login handler to verify passwords correctly, allowing unauthorised access. If your installation has never used the LDAP or TextFile login handlers, or never used legacy login at all, then it is not affected. Still, we recommend installing the update, to be on the safe side. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/13f03a2be6c0ee4d0caaafaef05904ea9b0c4d9d Affected versions
v2018.09.0
v2018.09.1
v2018.06.0
v2018.06.1
v2018.06.1.1
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
+ 35 more Show less
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
Fixed in
5.3.12.4
5.4.12.1
2017.12.4.1
2018.6.1.2
2018.9.1.1
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-2vh3-cj9j-mcj5
May 15, 2024
eZ Publish Legacy Cross-site Scripting (XSS) in 'disabled module' error template
Medium
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy via the LegacyBridge. Installations where all modules are disabled may be vulnerable to XSS injection in the module name. This is a rare configuration, but we still recommend installing the update, which adds the necessary input washing. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/4697bff700e8cf95d5847ea19dad3479a77b02d9 Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
+ 38 more Show less
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
Fixed in
5.3.12.5
5.4.12.2
2017.12.4.2
2018.6.1.3
2018.9.1.2
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-10806
GHSA-54p5-gxq6-j98g
May 24, 2022
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. Affected versions
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
+ 17 more Show less
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
Fixed in
5.4.14.1
2017.12.7.2
2019.03.4.2
References Updated Dec 08, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2018.09.0
minor
4 CVEs
GHSA-pqjm-xcp8-wgmm
May 15, 2024
Ez Platform and Legacy are prone to an insecure interpretation of PHP/PHAR uploads
Medium
The eZ Platform and Legacy are affected by an issue related to how uploaded PHP and PHAR files are handled, and consists of two parts: 1. Web server configuration, and 2. Disabling the PHAR stream wrapper. 1. WEB SERVER CONFIGURATION The sample web server configuration in our documentation can in some cases allow the execution of uploaded PHP/PHAR code. This can be abused to allow priviledge escalation and breach of content access controls, among other things. Please ensure that your web server will not execute files in directories were files may be uploaded, such as web/var/ and ezpublish_legacy/var/ As an example, here is how you can make Apache return HTTP 403 Forbidden for a number of executable file types in your eZ Platform var directory. Please adapt it to your needs. It is then possible to enable logging of HTTP 403 in a separate log file if you wish, you could do this to see if someone is trying to abuse the server.
Here is the same configuration, but for the Nginx web server:
2. DISABLE PHAR STREAM WRAPPER PHAR archives may be crafted such that its stream wrapper will execute them without being specifically asked to. With such files, any PHP file operation may cause deserialisation and execution. This may happen even if the file name suffix isn't ".phar". Any site that allows file uploads is at risk. Normally eZ Platform has no need for PHAR support. It's only used by Composer, and that is executed separately from eZ Platform. So one way to avoid this vulnerability is to disable the PHAR stream wrapper within eZ Platform. (If you know you need PHAR support, please consider other means to deal with this vulnerability. For example, enabling the wrapper only in those scripts/bundles that have to deal with such files.) Disabling the stream wrapper should be done in: eZ Platform (web/app.php) CLI scripts (bin/console) Legacy (index.php and CLI scripts) To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezplatform/commit/9a0c52dc4535e4b3ce379f80222dc53f705a2cfd https://github.com/ezsystems/ezpublish-legacy/commit/d21957bf202b091ab39dfb5be300f6c30be3933e Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
2013.04.0
v2013.05.0
v2013.06.0
+ 41 more Show less
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
Fixed in
5.3.12.6
5.4.12.3
2017.12.4.3
2018.6.1.4
2018.9.1.3
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-p9mp-vq4v-v5m5
May 15, 2024
eZ Publish Legacy Passwordless login for LDAP users
High
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy. Installations that are using the legacy LDAP login handler or the TextFile login handler in combination with the standard legacy login handler, may in rare cases be vulnerable to a failure of the standard login handler to verify passwords correctly, allowing unauthorised access. If your installation has never used the LDAP or TextFile login handlers, or never used legacy login at all, then it is not affected. Still, we recommend installing the update, to be on the safe side. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/13f03a2be6c0ee4d0caaafaef05904ea9b0c4d9d Affected versions
v2018.09.0
v2018.09.1
v2018.06.0
v2018.06.1
v2018.06.1.1
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
+ 35 more Show less
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
Fixed in
5.3.12.4
5.4.12.1
2017.12.4.1
2018.6.1.2
2018.9.1.1
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-2vh3-cj9j-mcj5
May 15, 2024
eZ Publish Legacy Cross-site Scripting (XSS) in 'disabled module' error template
Medium
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy via the LegacyBridge. Installations where all modules are disabled may be vulnerable to XSS injection in the module name. This is a rare configuration, but we still recommend installing the update, which adds the necessary input washing. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/4697bff700e8cf95d5847ea19dad3479a77b02d9 Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
+ 38 more Show less
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
Fixed in
5.3.12.5
5.4.12.2
2017.12.4.2
2018.6.1.3
2018.9.1.2
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2018.06.1.1
patch
4 CVEs
GHSA-pqjm-xcp8-wgmm
May 15, 2024
Ez Platform and Legacy are prone to an insecure interpretation of PHP/PHAR uploads
Medium
The eZ Platform and Legacy are affected by an issue related to how uploaded PHP and PHAR files are handled, and consists of two parts: 1. Web server configuration, and 2. Disabling the PHAR stream wrapper. 1. WEB SERVER CONFIGURATION The sample web server configuration in our documentation can in some cases allow the execution of uploaded PHP/PHAR code. This can be abused to allow priviledge escalation and breach of content access controls, among other things. Please ensure that your web server will not execute files in directories were files may be uploaded, such as web/var/ and ezpublish_legacy/var/ As an example, here is how you can make Apache return HTTP 403 Forbidden for a number of executable file types in your eZ Platform var directory. Please adapt it to your needs. It is then possible to enable logging of HTTP 403 in a separate log file if you wish, you could do this to see if someone is trying to abuse the server.
Here is the same configuration, but for the Nginx web server:
2. DISABLE PHAR STREAM WRAPPER PHAR archives may be crafted such that its stream wrapper will execute them without being specifically asked to. With such files, any PHP file operation may cause deserialisation and execution. This may happen even if the file name suffix isn't ".phar". Any site that allows file uploads is at risk. Normally eZ Platform has no need for PHAR support. It's only used by Composer, and that is executed separately from eZ Platform. So one way to avoid this vulnerability is to disable the PHAR stream wrapper within eZ Platform. (If you know you need PHAR support, please consider other means to deal with this vulnerability. For example, enabling the wrapper only in those scripts/bundles that have to deal with such files.) Disabling the stream wrapper should be done in: eZ Platform (web/app.php) CLI scripts (bin/console) Legacy (index.php and CLI scripts) To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezplatform/commit/9a0c52dc4535e4b3ce379f80222dc53f705a2cfd https://github.com/ezsystems/ezpublish-legacy/commit/d21957bf202b091ab39dfb5be300f6c30be3933e Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
2013.04.0
v2013.05.0
v2013.06.0
+ 41 more Show less
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
Fixed in
5.3.12.6
5.4.12.3
2017.12.4.3
2018.6.1.4
2018.9.1.3
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-p9mp-vq4v-v5m5
May 15, 2024
eZ Publish Legacy Passwordless login for LDAP users
High
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy. Installations that are using the legacy LDAP login handler or the TextFile login handler in combination with the standard legacy login handler, may in rare cases be vulnerable to a failure of the standard login handler to verify passwords correctly, allowing unauthorised access. If your installation has never used the LDAP or TextFile login handlers, or never used legacy login at all, then it is not affected. Still, we recommend installing the update, to be on the safe side. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/13f03a2be6c0ee4d0caaafaef05904ea9b0c4d9d Affected versions
v2018.09.0
v2018.09.1
v2018.06.0
v2018.06.1
v2018.06.1.1
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
+ 35 more Show less
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
Fixed in
5.3.12.4
5.4.12.1
2017.12.4.1
2018.6.1.2
2018.9.1.1
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-2vh3-cj9j-mcj5
May 15, 2024
eZ Publish Legacy Cross-site Scripting (XSS) in 'disabled module' error template
Medium
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy via the LegacyBridge. Installations where all modules are disabled may be vulnerable to XSS injection in the module name. This is a rare configuration, but we still recommend installing the update, which adds the necessary input washing. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/4697bff700e8cf95d5847ea19dad3479a77b02d9 Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
+ 38 more Show less
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
Fixed in
5.3.12.5
5.4.12.2
2017.12.4.2
2018.6.1.3
2018.9.1.2
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2017.12.3.2
patch
7 CVEs
GHSA-39j2-4p9j-5w4j
May 15, 2024
Ez Platform Object Injection in legacy shop module
Medium
This Security Advisory is about a vulnerability in the Legacy shop module. A backend editor could perform object injection in discount rules. This would require backend access and permission to edit discount rules. While object injection in itself is a serious vulnerability, the permission requirement means that normally only administrators would be able to exploit it, that's why it was classified as Medium severity. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
+ 12 more Show less
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
Fixed in
5.4.14.2
2017.12.7.3
2019.3.5.1
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-9895-26wr-4fgv
May 15, 2024
EZsystems Remote code execution in file uploads
High
This Security Advisory is about a vulnerability in the way eZ Platform and eZ Publish Legacy handles file uploads, which can in the worst case lead to remote code execution (RCE), a very serious threat. An attacker would need access to uploading files to be able to exploit the vulnerability, so if you have strict controls on this and trust all who have this permission, you're not affected. On the basis of the tests we have made, we also believe the vulnerability cannot be exploited as long as our recommended vhost configuration is used. Here is the v2.5 recommendation for Nginx, as an example: https://github.com/ezsystems/ezplatform/blob/2.5/doc/nginx/vhost.template#L31 This vhost template specifies that only the file app.php in the web root is executed, while vulnerable configurations allow execution of any php file. Apache is affected in the same way as Nginx, and is also protected by using the recommended configuration. The build-in webserver in PHP stays vulnerable, as it doesn't use this type of configuration (this webserver should only be used for development, never for production). We cannot be 100% certain our configuration is not vulnerable. We also do not know if all our users use the recommended configuration, so we send out this fix to be on the safe side. The fix includes a blacklist feature for uploaded filenames, such as ".php". The file types on the blacklist cannot be uploaded. The blacklist is configurable. In eZ Platform you will find it as ezsettings.default.io.file_storage.file_type_blacklist in eZ/Bundle/EzPublishCoreBundle/Resources/config/default_settings.yml in vendors/ezsystems/ezpublish-kernel. In eZ Publish Legacy you will find it as FileExtensionBlackList in settings/file.ini. By default it blocks these file types: php, php3, phar, phpt, pht, phtml, pgif. The fix also inclues a new block against path traversal attacks, though this kind of attack was not reproducible in our tests. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
+ 9 more Show less
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
Fixed in
5.4.14.1
2017.12.7.2
2019.3.4.2
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-pqjm-xcp8-wgmm
May 15, 2024
Ez Platform and Legacy are prone to an insecure interpretation of PHP/PHAR uploads
Medium
The eZ Platform and Legacy are affected by an issue related to how uploaded PHP and PHAR files are handled, and consists of two parts: 1. Web server configuration, and 2. Disabling the PHAR stream wrapper. 1. WEB SERVER CONFIGURATION The sample web server configuration in our documentation can in some cases allow the execution of uploaded PHP/PHAR code. This can be abused to allow priviledge escalation and breach of content access controls, among other things. Please ensure that your web server will not execute files in directories were files may be uploaded, such as web/var/ and ezpublish_legacy/var/ As an example, here is how you can make Apache return HTTP 403 Forbidden for a number of executable file types in your eZ Platform var directory. Please adapt it to your needs. It is then possible to enable logging of HTTP 403 in a separate log file if you wish, you could do this to see if someone is trying to abuse the server.
Here is the same configuration, but for the Nginx web server:
2. DISABLE PHAR STREAM WRAPPER PHAR archives may be crafted such that its stream wrapper will execute them without being specifically asked to. With such files, any PHP file operation may cause deserialisation and execution. This may happen even if the file name suffix isn't ".phar". Any site that allows file uploads is at risk. Normally eZ Platform has no need for PHAR support. It's only used by Composer, and that is executed separately from eZ Platform. So one way to avoid this vulnerability is to disable the PHAR stream wrapper within eZ Platform. (If you know you need PHAR support, please consider other means to deal with this vulnerability. For example, enabling the wrapper only in those scripts/bundles that have to deal with such files.) Disabling the stream wrapper should be done in: eZ Platform (web/app.php) CLI scripts (bin/console) Legacy (index.php and CLI scripts) To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezplatform/commit/9a0c52dc4535e4b3ce379f80222dc53f705a2cfd https://github.com/ezsystems/ezpublish-legacy/commit/d21957bf202b091ab39dfb5be300f6c30be3933e Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
2013.04.0
v2013.05.0
v2013.06.0
+ 41 more Show less
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
Fixed in
5.3.12.6
5.4.12.3
2017.12.4.3
2018.6.1.4
2018.9.1.3
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-p9mp-vq4v-v5m5
May 15, 2024
eZ Publish Legacy Passwordless login for LDAP users
High
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy. Installations that are using the legacy LDAP login handler or the TextFile login handler in combination with the standard legacy login handler, may in rare cases be vulnerable to a failure of the standard login handler to verify passwords correctly, allowing unauthorised access. If your installation has never used the LDAP or TextFile login handlers, or never used legacy login at all, then it is not affected. Still, we recommend installing the update, to be on the safe side. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/13f03a2be6c0ee4d0caaafaef05904ea9b0c4d9d Affected versions
v2018.09.0
v2018.09.1
v2018.06.0
v2018.06.1
v2018.06.1.1
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
+ 35 more Show less
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
Fixed in
5.3.12.4
5.4.12.1
2017.12.4.1
2018.6.1.2
2018.9.1.1
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-2vh3-cj9j-mcj5
May 15, 2024
eZ Publish Legacy Cross-site Scripting (XSS) in 'disabled module' error template
Medium
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy via the LegacyBridge. Installations where all modules are disabled may be vulnerable to XSS injection in the module name. This is a rare configuration, but we still recommend installing the update, which adds the necessary input washing. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/4697bff700e8cf95d5847ea19dad3479a77b02d9 Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
+ 38 more Show less
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
Fixed in
5.3.12.5
5.4.12.2
2017.12.4.2
2018.6.1.3
2018.9.1.2
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-10806
GHSA-54p5-gxq6-j98g
May 24, 2022
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. Affected versions
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
+ 17 more Show less
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
Fixed in
5.4.14.1
2017.12.7.2
2019.03.4.2
References Updated Dec 08, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev |
v2017.12.3.2
patch
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
v2018.06.1
patch
4 CVEs
GHSA-pqjm-xcp8-wgmm
May 15, 2024
Ez Platform and Legacy are prone to an insecure interpretation of PHP/PHAR uploads
Medium
The eZ Platform and Legacy are affected by an issue related to how uploaded PHP and PHAR files are handled, and consists of two parts: 1. Web server configuration, and 2. Disabling the PHAR stream wrapper. 1. WEB SERVER CONFIGURATION The sample web server configuration in our documentation can in some cases allow the execution of uploaded PHP/PHAR code. This can be abused to allow priviledge escalation and breach of content access controls, among other things. Please ensure that your web server will not execute files in directories were files may be uploaded, such as web/var/ and ezpublish_legacy/var/ As an example, here is how you can make Apache return HTTP 403 Forbidden for a number of executable file types in your eZ Platform var directory. Please adapt it to your needs. It is then possible to enable logging of HTTP 403 in a separate log file if you wish, you could do this to see if someone is trying to abuse the server.
Here is the same configuration, but for the Nginx web server:
2. DISABLE PHAR STREAM WRAPPER PHAR archives may be crafted such that its stream wrapper will execute them without being specifically asked to. With such files, any PHP file operation may cause deserialisation and execution. This may happen even if the file name suffix isn't ".phar". Any site that allows file uploads is at risk. Normally eZ Platform has no need for PHAR support. It's only used by Composer, and that is executed separately from eZ Platform. So one way to avoid this vulnerability is to disable the PHAR stream wrapper within eZ Platform. (If you know you need PHAR support, please consider other means to deal with this vulnerability. For example, enabling the wrapper only in those scripts/bundles that have to deal with such files.) Disabling the stream wrapper should be done in: eZ Platform (web/app.php) CLI scripts (bin/console) Legacy (index.php and CLI scripts) To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezplatform/commit/9a0c52dc4535e4b3ce379f80222dc53f705a2cfd https://github.com/ezsystems/ezpublish-legacy/commit/d21957bf202b091ab39dfb5be300f6c30be3933e Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
2013.04.0
v2013.05.0
v2013.06.0
+ 41 more Show less
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
Fixed in
5.3.12.6
5.4.12.3
2017.12.4.3
2018.6.1.4
2018.9.1.3
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-p9mp-vq4v-v5m5
May 15, 2024
eZ Publish Legacy Passwordless login for LDAP users
High
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy. Installations that are using the legacy LDAP login handler or the TextFile login handler in combination with the standard legacy login handler, may in rare cases be vulnerable to a failure of the standard login handler to verify passwords correctly, allowing unauthorised access. If your installation has never used the LDAP or TextFile login handlers, or never used legacy login at all, then it is not affected. Still, we recommend installing the update, to be on the safe side. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/13f03a2be6c0ee4d0caaafaef05904ea9b0c4d9d Affected versions
v2018.09.0
v2018.09.1
v2018.06.0
v2018.06.1
v2018.06.1.1
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
+ 35 more Show less
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
Fixed in
5.3.12.4
5.4.12.1
2017.12.4.1
2018.6.1.2
2018.9.1.1
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-2vh3-cj9j-mcj5
May 15, 2024
eZ Publish Legacy Cross-site Scripting (XSS) in 'disabled module' error template
Medium
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy via the LegacyBridge. Installations where all modules are disabled may be vulnerable to XSS injection in the module name. This is a rare configuration, but we still recommend installing the update, which adds the necessary input washing. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/4697bff700e8cf95d5847ea19dad3479a77b02d9 Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
+ 38 more Show less
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
Fixed in
5.3.12.5
5.4.12.2
2017.12.4.2
2018.6.1.3
2018.9.1.2
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2017.12.3.1
patch
7 CVEs
GHSA-39j2-4p9j-5w4j
May 15, 2024
Ez Platform Object Injection in legacy shop module
Medium
This Security Advisory is about a vulnerability in the Legacy shop module. A backend editor could perform object injection in discount rules. This would require backend access and permission to edit discount rules. While object injection in itself is a serious vulnerability, the permission requirement means that normally only administrators would be able to exploit it, that's why it was classified as Medium severity. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
+ 12 more Show less
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
Fixed in
5.4.14.2
2017.12.7.3
2019.3.5.1
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-9895-26wr-4fgv
May 15, 2024
EZsystems Remote code execution in file uploads
High
This Security Advisory is about a vulnerability in the way eZ Platform and eZ Publish Legacy handles file uploads, which can in the worst case lead to remote code execution (RCE), a very serious threat. An attacker would need access to uploading files to be able to exploit the vulnerability, so if you have strict controls on this and trust all who have this permission, you're not affected. On the basis of the tests we have made, we also believe the vulnerability cannot be exploited as long as our recommended vhost configuration is used. Here is the v2.5 recommendation for Nginx, as an example: https://github.com/ezsystems/ezplatform/blob/2.5/doc/nginx/vhost.template#L31 This vhost template specifies that only the file app.php in the web root is executed, while vulnerable configurations allow execution of any php file. Apache is affected in the same way as Nginx, and is also protected by using the recommended configuration. The build-in webserver in PHP stays vulnerable, as it doesn't use this type of configuration (this webserver should only be used for development, never for production). We cannot be 100% certain our configuration is not vulnerable. We also do not know if all our users use the recommended configuration, so we send out this fix to be on the safe side. The fix includes a blacklist feature for uploaded filenames, such as ".php". The file types on the blacklist cannot be uploaded. The blacklist is configurable. In eZ Platform you will find it as ezsettings.default.io.file_storage.file_type_blacklist in eZ/Bundle/EzPublishCoreBundle/Resources/config/default_settings.yml in vendors/ezsystems/ezpublish-kernel. In eZ Publish Legacy you will find it as FileExtensionBlackList in settings/file.ini. By default it blocks these file types: php, php3, phar, phpt, pht, phtml, pgif. The fix also inclues a new block against path traversal attacks, though this kind of attack was not reproducible in our tests. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
+ 9 more Show less
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
Fixed in
5.4.14.1
2017.12.7.2
2019.3.4.2
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-pqjm-xcp8-wgmm
May 15, 2024
Ez Platform and Legacy are prone to an insecure interpretation of PHP/PHAR uploads
Medium
The eZ Platform and Legacy are affected by an issue related to how uploaded PHP and PHAR files are handled, and consists of two parts: 1. Web server configuration, and 2. Disabling the PHAR stream wrapper. 1. WEB SERVER CONFIGURATION The sample web server configuration in our documentation can in some cases allow the execution of uploaded PHP/PHAR code. This can be abused to allow priviledge escalation and breach of content access controls, among other things. Please ensure that your web server will not execute files in directories were files may be uploaded, such as web/var/ and ezpublish_legacy/var/ As an example, here is how you can make Apache return HTTP 403 Forbidden for a number of executable file types in your eZ Platform var directory. Please adapt it to your needs. It is then possible to enable logging of HTTP 403 in a separate log file if you wish, you could do this to see if someone is trying to abuse the server.
Here is the same configuration, but for the Nginx web server:
2. DISABLE PHAR STREAM WRAPPER PHAR archives may be crafted such that its stream wrapper will execute them without being specifically asked to. With such files, any PHP file operation may cause deserialisation and execution. This may happen even if the file name suffix isn't ".phar". Any site that allows file uploads is at risk. Normally eZ Platform has no need for PHAR support. It's only used by Composer, and that is executed separately from eZ Platform. So one way to avoid this vulnerability is to disable the PHAR stream wrapper within eZ Platform. (If you know you need PHAR support, please consider other means to deal with this vulnerability. For example, enabling the wrapper only in those scripts/bundles that have to deal with such files.) Disabling the stream wrapper should be done in: eZ Platform (web/app.php) CLI scripts (bin/console) Legacy (index.php and CLI scripts) To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezplatform/commit/9a0c52dc4535e4b3ce379f80222dc53f705a2cfd https://github.com/ezsystems/ezpublish-legacy/commit/d21957bf202b091ab39dfb5be300f6c30be3933e Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
2013.04.0
v2013.05.0
v2013.06.0
+ 41 more Show less
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
Fixed in
5.3.12.6
5.4.12.3
2017.12.4.3
2018.6.1.4
2018.9.1.3
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-p9mp-vq4v-v5m5
May 15, 2024
eZ Publish Legacy Passwordless login for LDAP users
High
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy. Installations that are using the legacy LDAP login handler or the TextFile login handler in combination with the standard legacy login handler, may in rare cases be vulnerable to a failure of the standard login handler to verify passwords correctly, allowing unauthorised access. If your installation has never used the LDAP or TextFile login handlers, or never used legacy login at all, then it is not affected. Still, we recommend installing the update, to be on the safe side. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/13f03a2be6c0ee4d0caaafaef05904ea9b0c4d9d Affected versions
v2018.09.0
v2018.09.1
v2018.06.0
v2018.06.1
v2018.06.1.1
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
+ 35 more Show less
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
Fixed in
5.3.12.4
5.4.12.1
2017.12.4.1
2018.6.1.2
2018.9.1.1
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-2vh3-cj9j-mcj5
May 15, 2024
eZ Publish Legacy Cross-site Scripting (XSS) in 'disabled module' error template
Medium
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy via the LegacyBridge. Installations where all modules are disabled may be vulnerable to XSS injection in the module name. This is a rare configuration, but we still recommend installing the update, which adds the necessary input washing. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/4697bff700e8cf95d5847ea19dad3479a77b02d9 Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
+ 38 more Show less
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
Fixed in
5.3.12.5
5.4.12.2
2017.12.4.2
2018.6.1.3
2018.9.1.2
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-10806
GHSA-54p5-gxq6-j98g
May 24, 2022
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. Affected versions
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
+ 17 more Show less
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
Fixed in
5.4.14.1
2017.12.7.2
2019.03.4.2
References Updated Dec 08, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2018.06.0
major
4 CVEs
GHSA-pqjm-xcp8-wgmm
May 15, 2024
Ez Platform and Legacy are prone to an insecure interpretation of PHP/PHAR uploads
Medium
The eZ Platform and Legacy are affected by an issue related to how uploaded PHP and PHAR files are handled, and consists of two parts: 1. Web server configuration, and 2. Disabling the PHAR stream wrapper. 1. WEB SERVER CONFIGURATION The sample web server configuration in our documentation can in some cases allow the execution of uploaded PHP/PHAR code. This can be abused to allow priviledge escalation and breach of content access controls, among other things. Please ensure that your web server will not execute files in directories were files may be uploaded, such as web/var/ and ezpublish_legacy/var/ As an example, here is how you can make Apache return HTTP 403 Forbidden for a number of executable file types in your eZ Platform var directory. Please adapt it to your needs. It is then possible to enable logging of HTTP 403 in a separate log file if you wish, you could do this to see if someone is trying to abuse the server.
Here is the same configuration, but for the Nginx web server:
2. DISABLE PHAR STREAM WRAPPER PHAR archives may be crafted such that its stream wrapper will execute them without being specifically asked to. With such files, any PHP file operation may cause deserialisation and execution. This may happen even if the file name suffix isn't ".phar". Any site that allows file uploads is at risk. Normally eZ Platform has no need for PHAR support. It's only used by Composer, and that is executed separately from eZ Platform. So one way to avoid this vulnerability is to disable the PHAR stream wrapper within eZ Platform. (If you know you need PHAR support, please consider other means to deal with this vulnerability. For example, enabling the wrapper only in those scripts/bundles that have to deal with such files.) Disabling the stream wrapper should be done in: eZ Platform (web/app.php) CLI scripts (bin/console) Legacy (index.php and CLI scripts) To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezplatform/commit/9a0c52dc4535e4b3ce379f80222dc53f705a2cfd https://github.com/ezsystems/ezpublish-legacy/commit/d21957bf202b091ab39dfb5be300f6c30be3933e Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
2013.04.0
v2013.05.0
v2013.06.0
+ 41 more Show less
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
Fixed in
5.3.12.6
5.4.12.3
2017.12.4.3
2018.6.1.4
2018.9.1.3
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-p9mp-vq4v-v5m5
May 15, 2024
eZ Publish Legacy Passwordless login for LDAP users
High
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy. Installations that are using the legacy LDAP login handler or the TextFile login handler in combination with the standard legacy login handler, may in rare cases be vulnerable to a failure of the standard login handler to verify passwords correctly, allowing unauthorised access. If your installation has never used the LDAP or TextFile login handlers, or never used legacy login at all, then it is not affected. Still, we recommend installing the update, to be on the safe side. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/13f03a2be6c0ee4d0caaafaef05904ea9b0c4d9d Affected versions
v2018.09.0
v2018.09.1
v2018.06.0
v2018.06.1
v2018.06.1.1
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
+ 35 more Show less
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
Fixed in
5.3.12.4
5.4.12.1
2017.12.4.1
2018.6.1.2
2018.9.1.1
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-2vh3-cj9j-mcj5
May 15, 2024
eZ Publish Legacy Cross-site Scripting (XSS) in 'disabled module' error template
Medium
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy via the LegacyBridge. Installations where all modules are disabled may be vulnerable to XSS injection in the module name. This is a rare configuration, but we still recommend installing the update, which adds the necessary input washing. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/4697bff700e8cf95d5847ea19dad3479a77b02d9 Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
+ 38 more Show less
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
Fixed in
5.3.12.5
5.4.12.2
2017.12.4.2
2018.6.1.3
2018.9.1.2
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2017.12.3
patch
7 CVEs
GHSA-39j2-4p9j-5w4j
May 15, 2024
Ez Platform Object Injection in legacy shop module
Medium
This Security Advisory is about a vulnerability in the Legacy shop module. A backend editor could perform object injection in discount rules. This would require backend access and permission to edit discount rules. While object injection in itself is a serious vulnerability, the permission requirement means that normally only administrators would be able to exploit it, that's why it was classified as Medium severity. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
+ 12 more Show less
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
Fixed in
5.4.14.2
2017.12.7.3
2019.3.5.1
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-9895-26wr-4fgv
May 15, 2024
EZsystems Remote code execution in file uploads
High
This Security Advisory is about a vulnerability in the way eZ Platform and eZ Publish Legacy handles file uploads, which can in the worst case lead to remote code execution (RCE), a very serious threat. An attacker would need access to uploading files to be able to exploit the vulnerability, so if you have strict controls on this and trust all who have this permission, you're not affected. On the basis of the tests we have made, we also believe the vulnerability cannot be exploited as long as our recommended vhost configuration is used. Here is the v2.5 recommendation for Nginx, as an example: https://github.com/ezsystems/ezplatform/blob/2.5/doc/nginx/vhost.template#L31 This vhost template specifies that only the file app.php in the web root is executed, while vulnerable configurations allow execution of any php file. Apache is affected in the same way as Nginx, and is also protected by using the recommended configuration. The build-in webserver in PHP stays vulnerable, as it doesn't use this type of configuration (this webserver should only be used for development, never for production). We cannot be 100% certain our configuration is not vulnerable. We also do not know if all our users use the recommended configuration, so we send out this fix to be on the safe side. The fix includes a blacklist feature for uploaded filenames, such as ".php". The file types on the blacklist cannot be uploaded. The blacklist is configurable. In eZ Platform you will find it as ezsettings.default.io.file_storage.file_type_blacklist in eZ/Bundle/EzPublishCoreBundle/Resources/config/default_settings.yml in vendors/ezsystems/ezpublish-kernel. In eZ Publish Legacy you will find it as FileExtensionBlackList in settings/file.ini. By default it blocks these file types: php, php3, phar, phpt, pht, phtml, pgif. The fix also inclues a new block against path traversal attacks, though this kind of attack was not reproducible in our tests. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
+ 9 more Show less
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
Fixed in
5.4.14.1
2017.12.7.2
2019.3.4.2
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-pqjm-xcp8-wgmm
May 15, 2024
Ez Platform and Legacy are prone to an insecure interpretation of PHP/PHAR uploads
Medium
The eZ Platform and Legacy are affected by an issue related to how uploaded PHP and PHAR files are handled, and consists of two parts: 1. Web server configuration, and 2. Disabling the PHAR stream wrapper. 1. WEB SERVER CONFIGURATION The sample web server configuration in our documentation can in some cases allow the execution of uploaded PHP/PHAR code. This can be abused to allow priviledge escalation and breach of content access controls, among other things. Please ensure that your web server will not execute files in directories were files may be uploaded, such as web/var/ and ezpublish_legacy/var/ As an example, here is how you can make Apache return HTTP 403 Forbidden for a number of executable file types in your eZ Platform var directory. Please adapt it to your needs. It is then possible to enable logging of HTTP 403 in a separate log file if you wish, you could do this to see if someone is trying to abuse the server.
Here is the same configuration, but for the Nginx web server:
2. DISABLE PHAR STREAM WRAPPER PHAR archives may be crafted such that its stream wrapper will execute them without being specifically asked to. With such files, any PHP file operation may cause deserialisation and execution. This may happen even if the file name suffix isn't ".phar". Any site that allows file uploads is at risk. Normally eZ Platform has no need for PHAR support. It's only used by Composer, and that is executed separately from eZ Platform. So one way to avoid this vulnerability is to disable the PHAR stream wrapper within eZ Platform. (If you know you need PHAR support, please consider other means to deal with this vulnerability. For example, enabling the wrapper only in those scripts/bundles that have to deal with such files.) Disabling the stream wrapper should be done in: eZ Platform (web/app.php) CLI scripts (bin/console) Legacy (index.php and CLI scripts) To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezplatform/commit/9a0c52dc4535e4b3ce379f80222dc53f705a2cfd https://github.com/ezsystems/ezpublish-legacy/commit/d21957bf202b091ab39dfb5be300f6c30be3933e Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
2013.04.0
v2013.05.0
v2013.06.0
+ 41 more Show less
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
Fixed in
5.3.12.6
5.4.12.3
2017.12.4.3
2018.6.1.4
2018.9.1.3
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-p9mp-vq4v-v5m5
May 15, 2024
eZ Publish Legacy Passwordless login for LDAP users
High
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy. Installations that are using the legacy LDAP login handler or the TextFile login handler in combination with the standard legacy login handler, may in rare cases be vulnerable to a failure of the standard login handler to verify passwords correctly, allowing unauthorised access. If your installation has never used the LDAP or TextFile login handlers, or never used legacy login at all, then it is not affected. Still, we recommend installing the update, to be on the safe side. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/13f03a2be6c0ee4d0caaafaef05904ea9b0c4d9d Affected versions
v2018.09.0
v2018.09.1
v2018.06.0
v2018.06.1
v2018.06.1.1
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
+ 35 more Show less
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
Fixed in
5.3.12.4
5.4.12.1
2017.12.4.1
2018.6.1.2
2018.9.1.1
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-2vh3-cj9j-mcj5
May 15, 2024
eZ Publish Legacy Cross-site Scripting (XSS) in 'disabled module' error template
Medium
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy via the LegacyBridge. Installations where all modules are disabled may be vulnerable to XSS injection in the module name. This is a rare configuration, but we still recommend installing the update, which adds the necessary input washing. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/4697bff700e8cf95d5847ea19dad3479a77b02d9 Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
+ 38 more Show less
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
Fixed in
5.3.12.5
5.4.12.2
2017.12.4.2
2018.6.1.3
2018.9.1.2
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-10806
GHSA-54p5-gxq6-j98g
May 24, 2022
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. Affected versions
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
+ 17 more Show less
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
Fixed in
5.4.14.1
2017.12.7.2
2019.03.4.2
References Updated Dec 08, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2017.12.2.2
patch
7 CVEs
GHSA-39j2-4p9j-5w4j
May 15, 2024
Ez Platform Object Injection in legacy shop module
Medium
This Security Advisory is about a vulnerability in the Legacy shop module. A backend editor could perform object injection in discount rules. This would require backend access and permission to edit discount rules. While object injection in itself is a serious vulnerability, the permission requirement means that normally only administrators would be able to exploit it, that's why it was classified as Medium severity. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
+ 12 more Show less
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
Fixed in
5.4.14.2
2017.12.7.3
2019.3.5.1
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-9895-26wr-4fgv
May 15, 2024
EZsystems Remote code execution in file uploads
High
This Security Advisory is about a vulnerability in the way eZ Platform and eZ Publish Legacy handles file uploads, which can in the worst case lead to remote code execution (RCE), a very serious threat. An attacker would need access to uploading files to be able to exploit the vulnerability, so if you have strict controls on this and trust all who have this permission, you're not affected. On the basis of the tests we have made, we also believe the vulnerability cannot be exploited as long as our recommended vhost configuration is used. Here is the v2.5 recommendation for Nginx, as an example: https://github.com/ezsystems/ezplatform/blob/2.5/doc/nginx/vhost.template#L31 This vhost template specifies that only the file app.php in the web root is executed, while vulnerable configurations allow execution of any php file. Apache is affected in the same way as Nginx, and is also protected by using the recommended configuration. The build-in webserver in PHP stays vulnerable, as it doesn't use this type of configuration (this webserver should only be used for development, never for production). We cannot be 100% certain our configuration is not vulnerable. We also do not know if all our users use the recommended configuration, so we send out this fix to be on the safe side. The fix includes a blacklist feature for uploaded filenames, such as ".php". The file types on the blacklist cannot be uploaded. The blacklist is configurable. In eZ Platform you will find it as ezsettings.default.io.file_storage.file_type_blacklist in eZ/Bundle/EzPublishCoreBundle/Resources/config/default_settings.yml in vendors/ezsystems/ezpublish-kernel. In eZ Publish Legacy you will find it as FileExtensionBlackList in settings/file.ini. By default it blocks these file types: php, php3, phar, phpt, pht, phtml, pgif. The fix also inclues a new block against path traversal attacks, though this kind of attack was not reproducible in our tests. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
+ 9 more Show less
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
Fixed in
5.4.14.1
2017.12.7.2
2019.3.4.2
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-pqjm-xcp8-wgmm
May 15, 2024
Ez Platform and Legacy are prone to an insecure interpretation of PHP/PHAR uploads
Medium
The eZ Platform and Legacy are affected by an issue related to how uploaded PHP and PHAR files are handled, and consists of two parts: 1. Web server configuration, and 2. Disabling the PHAR stream wrapper. 1. WEB SERVER CONFIGURATION The sample web server configuration in our documentation can in some cases allow the execution of uploaded PHP/PHAR code. This can be abused to allow priviledge escalation and breach of content access controls, among other things. Please ensure that your web server will not execute files in directories were files may be uploaded, such as web/var/ and ezpublish_legacy/var/ As an example, here is how you can make Apache return HTTP 403 Forbidden for a number of executable file types in your eZ Platform var directory. Please adapt it to your needs. It is then possible to enable logging of HTTP 403 in a separate log file if you wish, you could do this to see if someone is trying to abuse the server.
Here is the same configuration, but for the Nginx web server:
2. DISABLE PHAR STREAM WRAPPER PHAR archives may be crafted such that its stream wrapper will execute them without being specifically asked to. With such files, any PHP file operation may cause deserialisation and execution. This may happen even if the file name suffix isn't ".phar". Any site that allows file uploads is at risk. Normally eZ Platform has no need for PHAR support. It's only used by Composer, and that is executed separately from eZ Platform. So one way to avoid this vulnerability is to disable the PHAR stream wrapper within eZ Platform. (If you know you need PHAR support, please consider other means to deal with this vulnerability. For example, enabling the wrapper only in those scripts/bundles that have to deal with such files.) Disabling the stream wrapper should be done in: eZ Platform (web/app.php) CLI scripts (bin/console) Legacy (index.php and CLI scripts) To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezplatform/commit/9a0c52dc4535e4b3ce379f80222dc53f705a2cfd https://github.com/ezsystems/ezpublish-legacy/commit/d21957bf202b091ab39dfb5be300f6c30be3933e Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
2013.04.0
v2013.05.0
v2013.06.0
+ 41 more Show less
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
Fixed in
5.3.12.6
5.4.12.3
2017.12.4.3
2018.6.1.4
2018.9.1.3
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-p9mp-vq4v-v5m5
May 15, 2024
eZ Publish Legacy Passwordless login for LDAP users
High
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy. Installations that are using the legacy LDAP login handler or the TextFile login handler in combination with the standard legacy login handler, may in rare cases be vulnerable to a failure of the standard login handler to verify passwords correctly, allowing unauthorised access. If your installation has never used the LDAP or TextFile login handlers, or never used legacy login at all, then it is not affected. Still, we recommend installing the update, to be on the safe side. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/13f03a2be6c0ee4d0caaafaef05904ea9b0c4d9d Affected versions
v2018.09.0
v2018.09.1
v2018.06.0
v2018.06.1
v2018.06.1.1
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
+ 35 more Show less
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
Fixed in
5.3.12.4
5.4.12.1
2017.12.4.1
2018.6.1.2
2018.9.1.1
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-2vh3-cj9j-mcj5
May 15, 2024
eZ Publish Legacy Cross-site Scripting (XSS) in 'disabled module' error template
Medium
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy via the LegacyBridge. Installations where all modules are disabled may be vulnerable to XSS injection in the module name. This is a rare configuration, but we still recommend installing the update, which adds the necessary input washing. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/4697bff700e8cf95d5847ea19dad3479a77b02d9 Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
+ 38 more Show less
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
Fixed in
5.3.12.5
5.4.12.2
2017.12.4.2
2018.6.1.3
2018.9.1.2
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-10806
GHSA-54p5-gxq6-j98g
May 24, 2022
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. Affected versions
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
+ 17 more Show less
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
Fixed in
5.4.14.1
2017.12.7.2
2019.03.4.2
References Updated Dec 08, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2017.12.2.1
patch
7 CVEs
GHSA-39j2-4p9j-5w4j
May 15, 2024
Ez Platform Object Injection in legacy shop module
Medium
This Security Advisory is about a vulnerability in the Legacy shop module. A backend editor could perform object injection in discount rules. This would require backend access and permission to edit discount rules. While object injection in itself is a serious vulnerability, the permission requirement means that normally only administrators would be able to exploit it, that's why it was classified as Medium severity. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
+ 12 more Show less
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
Fixed in
5.4.14.2
2017.12.7.3
2019.3.5.1
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-9895-26wr-4fgv
May 15, 2024
EZsystems Remote code execution in file uploads
High
This Security Advisory is about a vulnerability in the way eZ Platform and eZ Publish Legacy handles file uploads, which can in the worst case lead to remote code execution (RCE), a very serious threat. An attacker would need access to uploading files to be able to exploit the vulnerability, so if you have strict controls on this and trust all who have this permission, you're not affected. On the basis of the tests we have made, we also believe the vulnerability cannot be exploited as long as our recommended vhost configuration is used. Here is the v2.5 recommendation for Nginx, as an example: https://github.com/ezsystems/ezplatform/blob/2.5/doc/nginx/vhost.template#L31 This vhost template specifies that only the file app.php in the web root is executed, while vulnerable configurations allow execution of any php file. Apache is affected in the same way as Nginx, and is also protected by using the recommended configuration. The build-in webserver in PHP stays vulnerable, as it doesn't use this type of configuration (this webserver should only be used for development, never for production). We cannot be 100% certain our configuration is not vulnerable. We also do not know if all our users use the recommended configuration, so we send out this fix to be on the safe side. The fix includes a blacklist feature for uploaded filenames, such as ".php". The file types on the blacklist cannot be uploaded. The blacklist is configurable. In eZ Platform you will find it as ezsettings.default.io.file_storage.file_type_blacklist in eZ/Bundle/EzPublishCoreBundle/Resources/config/default_settings.yml in vendors/ezsystems/ezpublish-kernel. In eZ Publish Legacy you will find it as FileExtensionBlackList in settings/file.ini. By default it blocks these file types: php, php3, phar, phpt, pht, phtml, pgif. The fix also inclues a new block against path traversal attacks, though this kind of attack was not reproducible in our tests. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
+ 9 more Show less
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
Fixed in
5.4.14.1
2017.12.7.2
2019.3.4.2
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-pqjm-xcp8-wgmm
May 15, 2024
Ez Platform and Legacy are prone to an insecure interpretation of PHP/PHAR uploads
Medium
The eZ Platform and Legacy are affected by an issue related to how uploaded PHP and PHAR files are handled, and consists of two parts: 1. Web server configuration, and 2. Disabling the PHAR stream wrapper. 1. WEB SERVER CONFIGURATION The sample web server configuration in our documentation can in some cases allow the execution of uploaded PHP/PHAR code. This can be abused to allow priviledge escalation and breach of content access controls, among other things. Please ensure that your web server will not execute files in directories were files may be uploaded, such as web/var/ and ezpublish_legacy/var/ As an example, here is how you can make Apache return HTTP 403 Forbidden for a number of executable file types in your eZ Platform var directory. Please adapt it to your needs. It is then possible to enable logging of HTTP 403 in a separate log file if you wish, you could do this to see if someone is trying to abuse the server.
Here is the same configuration, but for the Nginx web server:
2. DISABLE PHAR STREAM WRAPPER PHAR archives may be crafted such that its stream wrapper will execute them without being specifically asked to. With such files, any PHP file operation may cause deserialisation and execution. This may happen even if the file name suffix isn't ".phar". Any site that allows file uploads is at risk. Normally eZ Platform has no need for PHAR support. It's only used by Composer, and that is executed separately from eZ Platform. So one way to avoid this vulnerability is to disable the PHAR stream wrapper within eZ Platform. (If you know you need PHAR support, please consider other means to deal with this vulnerability. For example, enabling the wrapper only in those scripts/bundles that have to deal with such files.) Disabling the stream wrapper should be done in: eZ Platform (web/app.php) CLI scripts (bin/console) Legacy (index.php and CLI scripts) To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezplatform/commit/9a0c52dc4535e4b3ce379f80222dc53f705a2cfd https://github.com/ezsystems/ezpublish-legacy/commit/d21957bf202b091ab39dfb5be300f6c30be3933e Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
2013.04.0
v2013.05.0
v2013.06.0
+ 41 more Show less
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
Fixed in
5.3.12.6
5.4.12.3
2017.12.4.3
2018.6.1.4
2018.9.1.3
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-p9mp-vq4v-v5m5
May 15, 2024
eZ Publish Legacy Passwordless login for LDAP users
High
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy. Installations that are using the legacy LDAP login handler or the TextFile login handler in combination with the standard legacy login handler, may in rare cases be vulnerable to a failure of the standard login handler to verify passwords correctly, allowing unauthorised access. If your installation has never used the LDAP or TextFile login handlers, or never used legacy login at all, then it is not affected. Still, we recommend installing the update, to be on the safe side. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/13f03a2be6c0ee4d0caaafaef05904ea9b0c4d9d Affected versions
v2018.09.0
v2018.09.1
v2018.06.0
v2018.06.1
v2018.06.1.1
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
+ 35 more Show less
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
Fixed in
5.3.12.4
5.4.12.1
2017.12.4.1
2018.6.1.2
2018.9.1.1
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-2vh3-cj9j-mcj5
May 15, 2024
eZ Publish Legacy Cross-site Scripting (XSS) in 'disabled module' error template
Medium
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy via the LegacyBridge. Installations where all modules are disabled may be vulnerable to XSS injection in the module name. This is a rare configuration, but we still recommend installing the update, which adds the necessary input washing. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/4697bff700e8cf95d5847ea19dad3479a77b02d9 Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
+ 38 more Show less
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
Fixed in
5.3.12.5
5.4.12.2
2017.12.4.2
2018.6.1.3
2018.9.1.2
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-10806
GHSA-54p5-gxq6-j98g
May 24, 2022
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. Affected versions
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
+ 17 more Show less
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
Fixed in
5.4.14.1
2017.12.7.2
2019.03.4.2
References Updated Dec 08, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2017.12.2
patch
8 CVEs
GHSA-39j2-4p9j-5w4j
May 15, 2024
Ez Platform Object Injection in legacy shop module
Medium
This Security Advisory is about a vulnerability in the Legacy shop module. A backend editor could perform object injection in discount rules. This would require backend access and permission to edit discount rules. While object injection in itself is a serious vulnerability, the permission requirement means that normally only administrators would be able to exploit it, that's why it was classified as Medium severity. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
+ 12 more Show less
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
Fixed in
5.4.14.2
2017.12.7.3
2019.3.5.1
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-9895-26wr-4fgv
May 15, 2024
EZsystems Remote code execution in file uploads
High
This Security Advisory is about a vulnerability in the way eZ Platform and eZ Publish Legacy handles file uploads, which can in the worst case lead to remote code execution (RCE), a very serious threat. An attacker would need access to uploading files to be able to exploit the vulnerability, so if you have strict controls on this and trust all who have this permission, you're not affected. On the basis of the tests we have made, we also believe the vulnerability cannot be exploited as long as our recommended vhost configuration is used. Here is the v2.5 recommendation for Nginx, as an example: https://github.com/ezsystems/ezplatform/blob/2.5/doc/nginx/vhost.template#L31 This vhost template specifies that only the file app.php in the web root is executed, while vulnerable configurations allow execution of any php file. Apache is affected in the same way as Nginx, and is also protected by using the recommended configuration. The build-in webserver in PHP stays vulnerable, as it doesn't use this type of configuration (this webserver should only be used for development, never for production). We cannot be 100% certain our configuration is not vulnerable. We also do not know if all our users use the recommended configuration, so we send out this fix to be on the safe side. The fix includes a blacklist feature for uploaded filenames, such as ".php". The file types on the blacklist cannot be uploaded. The blacklist is configurable. In eZ Platform you will find it as ezsettings.default.io.file_storage.file_type_blacklist in eZ/Bundle/EzPublishCoreBundle/Resources/config/default_settings.yml in vendors/ezsystems/ezpublish-kernel. In eZ Publish Legacy you will find it as FileExtensionBlackList in settings/file.ini. By default it blocks these file types: php, php3, phar, phpt, pht, phtml, pgif. The fix also inclues a new block against path traversal attacks, though this kind of attack was not reproducible in our tests. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
+ 9 more Show less
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
Fixed in
5.4.14.1
2017.12.7.2
2019.3.4.2
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-pqjm-xcp8-wgmm
May 15, 2024
Ez Platform and Legacy are prone to an insecure interpretation of PHP/PHAR uploads
Medium
The eZ Platform and Legacy are affected by an issue related to how uploaded PHP and PHAR files are handled, and consists of two parts: 1. Web server configuration, and 2. Disabling the PHAR stream wrapper. 1. WEB SERVER CONFIGURATION The sample web server configuration in our documentation can in some cases allow the execution of uploaded PHP/PHAR code. This can be abused to allow priviledge escalation and breach of content access controls, among other things. Please ensure that your web server will not execute files in directories were files may be uploaded, such as web/var/ and ezpublish_legacy/var/ As an example, here is how you can make Apache return HTTP 403 Forbidden for a number of executable file types in your eZ Platform var directory. Please adapt it to your needs. It is then possible to enable logging of HTTP 403 in a separate log file if you wish, you could do this to see if someone is trying to abuse the server.
Here is the same configuration, but for the Nginx web server:
2. DISABLE PHAR STREAM WRAPPER PHAR archives may be crafted such that its stream wrapper will execute them without being specifically asked to. With such files, any PHP file operation may cause deserialisation and execution. This may happen even if the file name suffix isn't ".phar". Any site that allows file uploads is at risk. Normally eZ Platform has no need for PHAR support. It's only used by Composer, and that is executed separately from eZ Platform. So one way to avoid this vulnerability is to disable the PHAR stream wrapper within eZ Platform. (If you know you need PHAR support, please consider other means to deal with this vulnerability. For example, enabling the wrapper only in those scripts/bundles that have to deal with such files.) Disabling the stream wrapper should be done in: eZ Platform (web/app.php) CLI scripts (bin/console) Legacy (index.php and CLI scripts) To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezplatform/commit/9a0c52dc4535e4b3ce379f80222dc53f705a2cfd https://github.com/ezsystems/ezpublish-legacy/commit/d21957bf202b091ab39dfb5be300f6c30be3933e Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
2013.04.0
v2013.05.0
v2013.06.0
+ 41 more Show less
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
Fixed in
5.3.12.6
5.4.12.3
2017.12.4.3
2018.6.1.4
2018.9.1.3
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-p9mp-vq4v-v5m5
May 15, 2024
eZ Publish Legacy Passwordless login for LDAP users
High
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy. Installations that are using the legacy LDAP login handler or the TextFile login handler in combination with the standard legacy login handler, may in rare cases be vulnerable to a failure of the standard login handler to verify passwords correctly, allowing unauthorised access. If your installation has never used the LDAP or TextFile login handlers, or never used legacy login at all, then it is not affected. Still, we recommend installing the update, to be on the safe side. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/13f03a2be6c0ee4d0caaafaef05904ea9b0c4d9d Affected versions
v2018.09.0
v2018.09.1
v2018.06.0
v2018.06.1
v2018.06.1.1
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
+ 35 more Show less
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
Fixed in
5.3.12.4
5.4.12.1
2017.12.4.1
2018.6.1.2
2018.9.1.1
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-2vh3-cj9j-mcj5
May 15, 2024
eZ Publish Legacy Cross-site Scripting (XSS) in 'disabled module' error template
Medium
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy via the LegacyBridge. Installations where all modules are disabled may be vulnerable to XSS injection in the module name. This is a rare configuration, but we still recommend installing the update, which adds the necessary input washing. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/4697bff700e8cf95d5847ea19dad3479a77b02d9 Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
+ 38 more Show less
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
Fixed in
5.3.12.5
5.4.12.2
2017.12.4.2
2018.6.1.3
2018.9.1.2
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-82rv-45pc-v28w
May 15, 2024
eZ Publish Legacy Patch EZSA-2018-001 for Several vulnerabilities
High
This security advisory fixes 4 separate vulnerabilities in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy by itself or via the LegacyBridge. First, it increases the randomness, and thus the security, of the pseudo-random bytes used to generate a hash for the "forgot password" feature. This protects accounts against being taken over through attacks trying to predict the hash. If the increased randomness is not available in your PHP installation, it will now log a warning. Second, it improves security of the information collector feature, by ensuring no collection emails will be sent from invalid manipulated forms. Third, it stops the possible leaking of the names of content objects that should not be readable for certain users, on installations where these users can create or edit XML text. Fourth, it protects against cross-site scripting (XSS) in the Matrix data type, on installations where users are allowed to edit content classes / content types. We recommend that you install the security update as soon as possible. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezpublish-legacy/commit/917711eb7ffe2b52a3e9fe12505f6810a63696f7 https://github.com/ezsystems/ezpublish-legacy/commit/6db0e6b7739481f27d954548388bd3f0ed2c6fdd https://github.com/ezsystems/ezpublish-legacy/commit/efcd2b61b15eaaf74e0ff28d6c723cf28e655dab https://github.com/ezsystems/ezpublish-legacy/commit/f9ffaf590b63b4f552142cfd4441afbbfb3f19b1 Affected versions
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
+ 24 more Show less
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
Fixed in
5.3.12.3
5.4.11.3
2017.12.2.1
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-10806
GHSA-54p5-gxq6-j98g
May 24, 2022
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. Affected versions
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
+ 17 more Show less
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
Fixed in
5.4.14.1
2017.12.7.2
2019.03.4.2
References Updated Dec 08, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2017.12.1.1
patch
8 CVEs
GHSA-39j2-4p9j-5w4j
May 15, 2024
Ez Platform Object Injection in legacy shop module
Medium
This Security Advisory is about a vulnerability in the Legacy shop module. A backend editor could perform object injection in discount rules. This would require backend access and permission to edit discount rules. While object injection in itself is a serious vulnerability, the permission requirement means that normally only administrators would be able to exploit it, that's why it was classified as Medium severity. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
+ 12 more Show less
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
Fixed in
5.4.14.2
2017.12.7.3
2019.3.5.1
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-9895-26wr-4fgv
May 15, 2024
EZsystems Remote code execution in file uploads
High
This Security Advisory is about a vulnerability in the way eZ Platform and eZ Publish Legacy handles file uploads, which can in the worst case lead to remote code execution (RCE), a very serious threat. An attacker would need access to uploading files to be able to exploit the vulnerability, so if you have strict controls on this and trust all who have this permission, you're not affected. On the basis of the tests we have made, we also believe the vulnerability cannot be exploited as long as our recommended vhost configuration is used. Here is the v2.5 recommendation for Nginx, as an example: https://github.com/ezsystems/ezplatform/blob/2.5/doc/nginx/vhost.template#L31 This vhost template specifies that only the file app.php in the web root is executed, while vulnerable configurations allow execution of any php file. Apache is affected in the same way as Nginx, and is also protected by using the recommended configuration. The build-in webserver in PHP stays vulnerable, as it doesn't use this type of configuration (this webserver should only be used for development, never for production). We cannot be 100% certain our configuration is not vulnerable. We also do not know if all our users use the recommended configuration, so we send out this fix to be on the safe side. The fix includes a blacklist feature for uploaded filenames, such as ".php". The file types on the blacklist cannot be uploaded. The blacklist is configurable. In eZ Platform you will find it as ezsettings.default.io.file_storage.file_type_blacklist in eZ/Bundle/EzPublishCoreBundle/Resources/config/default_settings.yml in vendors/ezsystems/ezpublish-kernel. In eZ Publish Legacy you will find it as FileExtensionBlackList in settings/file.ini. By default it blocks these file types: php, php3, phar, phpt, pht, phtml, pgif. The fix also inclues a new block against path traversal attacks, though this kind of attack was not reproducible in our tests. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
+ 9 more Show less
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
Fixed in
5.4.14.1
2017.12.7.2
2019.3.4.2
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-pqjm-xcp8-wgmm
May 15, 2024
Ez Platform and Legacy are prone to an insecure interpretation of PHP/PHAR uploads
Medium
The eZ Platform and Legacy are affected by an issue related to how uploaded PHP and PHAR files are handled, and consists of two parts: 1. Web server configuration, and 2. Disabling the PHAR stream wrapper. 1. WEB SERVER CONFIGURATION The sample web server configuration in our documentation can in some cases allow the execution of uploaded PHP/PHAR code. This can be abused to allow priviledge escalation and breach of content access controls, among other things. Please ensure that your web server will not execute files in directories were files may be uploaded, such as web/var/ and ezpublish_legacy/var/ As an example, here is how you can make Apache return HTTP 403 Forbidden for a number of executable file types in your eZ Platform var directory. Please adapt it to your needs. It is then possible to enable logging of HTTP 403 in a separate log file if you wish, you could do this to see if someone is trying to abuse the server.
Here is the same configuration, but for the Nginx web server:
2. DISABLE PHAR STREAM WRAPPER PHAR archives may be crafted such that its stream wrapper will execute them without being specifically asked to. With such files, any PHP file operation may cause deserialisation and execution. This may happen even if the file name suffix isn't ".phar". Any site that allows file uploads is at risk. Normally eZ Platform has no need for PHAR support. It's only used by Composer, and that is executed separately from eZ Platform. So one way to avoid this vulnerability is to disable the PHAR stream wrapper within eZ Platform. (If you know you need PHAR support, please consider other means to deal with this vulnerability. For example, enabling the wrapper only in those scripts/bundles that have to deal with such files.) Disabling the stream wrapper should be done in: eZ Platform (web/app.php) CLI scripts (bin/console) Legacy (index.php and CLI scripts) To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezplatform/commit/9a0c52dc4535e4b3ce379f80222dc53f705a2cfd https://github.com/ezsystems/ezpublish-legacy/commit/d21957bf202b091ab39dfb5be300f6c30be3933e Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
2013.04.0
v2013.05.0
v2013.06.0
+ 41 more Show less
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
Fixed in
5.3.12.6
5.4.12.3
2017.12.4.3
2018.6.1.4
2018.9.1.3
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-p9mp-vq4v-v5m5
May 15, 2024
eZ Publish Legacy Passwordless login for LDAP users
High
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy. Installations that are using the legacy LDAP login handler or the TextFile login handler in combination with the standard legacy login handler, may in rare cases be vulnerable to a failure of the standard login handler to verify passwords correctly, allowing unauthorised access. If your installation has never used the LDAP or TextFile login handlers, or never used legacy login at all, then it is not affected. Still, we recommend installing the update, to be on the safe side. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/13f03a2be6c0ee4d0caaafaef05904ea9b0c4d9d Affected versions
v2018.09.0
v2018.09.1
v2018.06.0
v2018.06.1
v2018.06.1.1
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
+ 35 more Show less
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
Fixed in
5.3.12.4
5.4.12.1
2017.12.4.1
2018.6.1.2
2018.9.1.1
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-2vh3-cj9j-mcj5
May 15, 2024
eZ Publish Legacy Cross-site Scripting (XSS) in 'disabled module' error template
Medium
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy via the LegacyBridge. Installations where all modules are disabled may be vulnerable to XSS injection in the module name. This is a rare configuration, but we still recommend installing the update, which adds the necessary input washing. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/4697bff700e8cf95d5847ea19dad3479a77b02d9 Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
+ 38 more Show less
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
Fixed in
5.3.12.5
5.4.12.2
2017.12.4.2
2018.6.1.3
2018.9.1.2
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-82rv-45pc-v28w
May 15, 2024
eZ Publish Legacy Patch EZSA-2018-001 for Several vulnerabilities
High
This security advisory fixes 4 separate vulnerabilities in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy by itself or via the LegacyBridge. First, it increases the randomness, and thus the security, of the pseudo-random bytes used to generate a hash for the "forgot password" feature. This protects accounts against being taken over through attacks trying to predict the hash. If the increased randomness is not available in your PHP installation, it will now log a warning. Second, it improves security of the information collector feature, by ensuring no collection emails will be sent from invalid manipulated forms. Third, it stops the possible leaking of the names of content objects that should not be readable for certain users, on installations where these users can create or edit XML text. Fourth, it protects against cross-site scripting (XSS) in the Matrix data type, on installations where users are allowed to edit content classes / content types. We recommend that you install the security update as soon as possible. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezpublish-legacy/commit/917711eb7ffe2b52a3e9fe12505f6810a63696f7 https://github.com/ezsystems/ezpublish-legacy/commit/6db0e6b7739481f27d954548388bd3f0ed2c6fdd https://github.com/ezsystems/ezpublish-legacy/commit/efcd2b61b15eaaf74e0ff28d6c723cf28e655dab https://github.com/ezsystems/ezpublish-legacy/commit/f9ffaf590b63b4f552142cfd4441afbbfb3f19b1 Affected versions
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
+ 24 more Show less
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
Fixed in
5.3.12.3
5.4.11.3
2017.12.2.1
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-10806
GHSA-54p5-gxq6-j98g
May 24, 2022
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. Affected versions
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
+ 17 more Show less
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
Fixed in
5.4.14.1
2017.12.7.2
2019.03.4.2
References Updated Dec 08, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2017.12.1
patch
8 CVEs
GHSA-39j2-4p9j-5w4j
May 15, 2024
Ez Platform Object Injection in legacy shop module
Medium
This Security Advisory is about a vulnerability in the Legacy shop module. A backend editor could perform object injection in discount rules. This would require backend access and permission to edit discount rules. While object injection in itself is a serious vulnerability, the permission requirement means that normally only administrators would be able to exploit it, that's why it was classified as Medium severity. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
+ 12 more Show less
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
Fixed in
5.4.14.2
2017.12.7.3
2019.3.5.1
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-9895-26wr-4fgv
May 15, 2024
EZsystems Remote code execution in file uploads
High
This Security Advisory is about a vulnerability in the way eZ Platform and eZ Publish Legacy handles file uploads, which can in the worst case lead to remote code execution (RCE), a very serious threat. An attacker would need access to uploading files to be able to exploit the vulnerability, so if you have strict controls on this and trust all who have this permission, you're not affected. On the basis of the tests we have made, we also believe the vulnerability cannot be exploited as long as our recommended vhost configuration is used. Here is the v2.5 recommendation for Nginx, as an example: https://github.com/ezsystems/ezplatform/blob/2.5/doc/nginx/vhost.template#L31 This vhost template specifies that only the file app.php in the web root is executed, while vulnerable configurations allow execution of any php file. Apache is affected in the same way as Nginx, and is also protected by using the recommended configuration. The build-in webserver in PHP stays vulnerable, as it doesn't use this type of configuration (this webserver should only be used for development, never for production). We cannot be 100% certain our configuration is not vulnerable. We also do not know if all our users use the recommended configuration, so we send out this fix to be on the safe side. The fix includes a blacklist feature for uploaded filenames, such as ".php". The file types on the blacklist cannot be uploaded. The blacklist is configurable. In eZ Platform you will find it as ezsettings.default.io.file_storage.file_type_blacklist in eZ/Bundle/EzPublishCoreBundle/Resources/config/default_settings.yml in vendors/ezsystems/ezpublish-kernel. In eZ Publish Legacy you will find it as FileExtensionBlackList in settings/file.ini. By default it blocks these file types: php, php3, phar, phpt, pht, phtml, pgif. The fix also inclues a new block against path traversal attacks, though this kind of attack was not reproducible in our tests. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
+ 9 more Show less
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
Fixed in
5.4.14.1
2017.12.7.2
2019.3.4.2
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-pqjm-xcp8-wgmm
May 15, 2024
Ez Platform and Legacy are prone to an insecure interpretation of PHP/PHAR uploads
Medium
The eZ Platform and Legacy are affected by an issue related to how uploaded PHP and PHAR files are handled, and consists of two parts: 1. Web server configuration, and 2. Disabling the PHAR stream wrapper. 1. WEB SERVER CONFIGURATION The sample web server configuration in our documentation can in some cases allow the execution of uploaded PHP/PHAR code. This can be abused to allow priviledge escalation and breach of content access controls, among other things. Please ensure that your web server will not execute files in directories were files may be uploaded, such as web/var/ and ezpublish_legacy/var/ As an example, here is how you can make Apache return HTTP 403 Forbidden for a number of executable file types in your eZ Platform var directory. Please adapt it to your needs. It is then possible to enable logging of HTTP 403 in a separate log file if you wish, you could do this to see if someone is trying to abuse the server.
Here is the same configuration, but for the Nginx web server:
2. DISABLE PHAR STREAM WRAPPER PHAR archives may be crafted such that its stream wrapper will execute them without being specifically asked to. With such files, any PHP file operation may cause deserialisation and execution. This may happen even if the file name suffix isn't ".phar". Any site that allows file uploads is at risk. Normally eZ Platform has no need for PHAR support. It's only used by Composer, and that is executed separately from eZ Platform. So one way to avoid this vulnerability is to disable the PHAR stream wrapper within eZ Platform. (If you know you need PHAR support, please consider other means to deal with this vulnerability. For example, enabling the wrapper only in those scripts/bundles that have to deal with such files.) Disabling the stream wrapper should be done in: eZ Platform (web/app.php) CLI scripts (bin/console) Legacy (index.php and CLI scripts) To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezplatform/commit/9a0c52dc4535e4b3ce379f80222dc53f705a2cfd https://github.com/ezsystems/ezpublish-legacy/commit/d21957bf202b091ab39dfb5be300f6c30be3933e Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
2013.04.0
v2013.05.0
v2013.06.0
+ 41 more Show less
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
Fixed in
5.3.12.6
5.4.12.3
2017.12.4.3
2018.6.1.4
2018.9.1.3
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-p9mp-vq4v-v5m5
May 15, 2024
eZ Publish Legacy Passwordless login for LDAP users
High
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy. Installations that are using the legacy LDAP login handler or the TextFile login handler in combination with the standard legacy login handler, may in rare cases be vulnerable to a failure of the standard login handler to verify passwords correctly, allowing unauthorised access. If your installation has never used the LDAP or TextFile login handlers, or never used legacy login at all, then it is not affected. Still, we recommend installing the update, to be on the safe side. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/13f03a2be6c0ee4d0caaafaef05904ea9b0c4d9d Affected versions
v2018.09.0
v2018.09.1
v2018.06.0
v2018.06.1
v2018.06.1.1
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
+ 35 more Show less
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
Fixed in
5.3.12.4
5.4.12.1
2017.12.4.1
2018.6.1.2
2018.9.1.1
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-2vh3-cj9j-mcj5
May 15, 2024
eZ Publish Legacy Cross-site Scripting (XSS) in 'disabled module' error template
Medium
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy via the LegacyBridge. Installations where all modules are disabled may be vulnerable to XSS injection in the module name. This is a rare configuration, but we still recommend installing the update, which adds the necessary input washing. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/4697bff700e8cf95d5847ea19dad3479a77b02d9 Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
+ 38 more Show less
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
Fixed in
5.3.12.5
5.4.12.2
2017.12.4.2
2018.6.1.3
2018.9.1.2
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-82rv-45pc-v28w
May 15, 2024
eZ Publish Legacy Patch EZSA-2018-001 for Several vulnerabilities
High
This security advisory fixes 4 separate vulnerabilities in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy by itself or via the LegacyBridge. First, it increases the randomness, and thus the security, of the pseudo-random bytes used to generate a hash for the "forgot password" feature. This protects accounts against being taken over through attacks trying to predict the hash. If the increased randomness is not available in your PHP installation, it will now log a warning. Second, it improves security of the information collector feature, by ensuring no collection emails will be sent from invalid manipulated forms. Third, it stops the possible leaking of the names of content objects that should not be readable for certain users, on installations where these users can create or edit XML text. Fourth, it protects against cross-site scripting (XSS) in the Matrix data type, on installations where users are allowed to edit content classes / content types. We recommend that you install the security update as soon as possible. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezpublish-legacy/commit/917711eb7ffe2b52a3e9fe12505f6810a63696f7 https://github.com/ezsystems/ezpublish-legacy/commit/6db0e6b7739481f27d954548388bd3f0ed2c6fdd https://github.com/ezsystems/ezpublish-legacy/commit/efcd2b61b15eaaf74e0ff28d6c723cf28e655dab https://github.com/ezsystems/ezpublish-legacy/commit/f9ffaf590b63b4f552142cfd4441afbbfb3f19b1 Affected versions
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
+ 24 more Show less
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
Fixed in
5.3.12.3
5.4.11.3
2017.12.2.1
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-10806
GHSA-54p5-gxq6-j98g
May 24, 2022
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. Affected versions
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
+ 17 more Show less
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
Fixed in
5.4.14.1
2017.12.7.2
2019.03.4.2
References Updated Dec 08, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2017.12.0
minor
8 CVEs
GHSA-39j2-4p9j-5w4j
May 15, 2024
Ez Platform Object Injection in legacy shop module
Medium
This Security Advisory is about a vulnerability in the Legacy shop module. A backend editor could perform object injection in discount rules. This would require backend access and permission to edit discount rules. While object injection in itself is a serious vulnerability, the permission requirement means that normally only administrators would be able to exploit it, that's why it was classified as Medium severity. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
+ 12 more Show less
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
Fixed in
5.4.14.2
2017.12.7.3
2019.3.5.1
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-9895-26wr-4fgv
May 15, 2024
EZsystems Remote code execution in file uploads
High
This Security Advisory is about a vulnerability in the way eZ Platform and eZ Publish Legacy handles file uploads, which can in the worst case lead to remote code execution (RCE), a very serious threat. An attacker would need access to uploading files to be able to exploit the vulnerability, so if you have strict controls on this and trust all who have this permission, you're not affected. On the basis of the tests we have made, we also believe the vulnerability cannot be exploited as long as our recommended vhost configuration is used. Here is the v2.5 recommendation for Nginx, as an example: https://github.com/ezsystems/ezplatform/blob/2.5/doc/nginx/vhost.template#L31 This vhost template specifies that only the file app.php in the web root is executed, while vulnerable configurations allow execution of any php file. Apache is affected in the same way as Nginx, and is also protected by using the recommended configuration. The build-in webserver in PHP stays vulnerable, as it doesn't use this type of configuration (this webserver should only be used for development, never for production). We cannot be 100% certain our configuration is not vulnerable. We also do not know if all our users use the recommended configuration, so we send out this fix to be on the safe side. The fix includes a blacklist feature for uploaded filenames, such as ".php". The file types on the blacklist cannot be uploaded. The blacklist is configurable. In eZ Platform you will find it as ezsettings.default.io.file_storage.file_type_blacklist in eZ/Bundle/EzPublishCoreBundle/Resources/config/default_settings.yml in vendors/ezsystems/ezpublish-kernel. In eZ Publish Legacy you will find it as FileExtensionBlackList in settings/file.ini. By default it blocks these file types: php, php3, phar, phpt, pht, phtml, pgif. The fix also inclues a new block against path traversal attacks, though this kind of attack was not reproducible in our tests. Affected versions
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
+ 9 more Show less
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
Fixed in
5.4.14.1
2017.12.7.2
2019.3.4.2
References Updated Nov 29, 2024 · Source: OSV.dev
GHSA-pqjm-xcp8-wgmm
May 15, 2024
Ez Platform and Legacy are prone to an insecure interpretation of PHP/PHAR uploads
Medium
The eZ Platform and Legacy are affected by an issue related to how uploaded PHP and PHAR files are handled, and consists of two parts: 1. Web server configuration, and 2. Disabling the PHAR stream wrapper. 1. WEB SERVER CONFIGURATION The sample web server configuration in our documentation can in some cases allow the execution of uploaded PHP/PHAR code. This can be abused to allow priviledge escalation and breach of content access controls, among other things. Please ensure that your web server will not execute files in directories were files may be uploaded, such as web/var/ and ezpublish_legacy/var/ As an example, here is how you can make Apache return HTTP 403 Forbidden for a number of executable file types in your eZ Platform var directory. Please adapt it to your needs. It is then possible to enable logging of HTTP 403 in a separate log file if you wish, you could do this to see if someone is trying to abuse the server.
Here is the same configuration, but for the Nginx web server:
2. DISABLE PHAR STREAM WRAPPER PHAR archives may be crafted such that its stream wrapper will execute them without being specifically asked to. With such files, any PHP file operation may cause deserialisation and execution. This may happen even if the file name suffix isn't ".phar". Any site that allows file uploads is at risk. Normally eZ Platform has no need for PHAR support. It's only used by Composer, and that is executed separately from eZ Platform. So one way to avoid this vulnerability is to disable the PHAR stream wrapper within eZ Platform. (If you know you need PHAR support, please consider other means to deal with this vulnerability. For example, enabling the wrapper only in those scripts/bundles that have to deal with such files.) Disabling the stream wrapper should be done in: eZ Platform (web/app.php) CLI scripts (bin/console) Legacy (index.php and CLI scripts) To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezplatform/commit/9a0c52dc4535e4b3ce379f80222dc53f705a2cfd https://github.com/ezsystems/ezpublish-legacy/commit/d21957bf202b091ab39dfb5be300f6c30be3933e Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
2013.04.0
v2013.05.0
v2013.06.0
+ 41 more Show less
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
Fixed in
5.3.12.6
5.4.12.3
2017.12.4.3
2018.6.1.4
2018.9.1.3
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-p9mp-vq4v-v5m5
May 15, 2024
eZ Publish Legacy Passwordless login for LDAP users
High
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy. Installations that are using the legacy LDAP login handler or the TextFile login handler in combination with the standard legacy login handler, may in rare cases be vulnerable to a failure of the standard login handler to verify passwords correctly, allowing unauthorised access. If your installation has never used the LDAP or TextFile login handlers, or never used legacy login at all, then it is not affected. Still, we recommend installing the update, to be on the safe side. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/13f03a2be6c0ee4d0caaafaef05904ea9b0c4d9d Affected versions
v2018.09.0
v2018.09.1
v2018.06.0
v2018.06.1
v2018.06.1.1
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
+ 35 more Show less
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
Fixed in
5.3.12.4
5.4.12.1
2017.12.4.1
2018.6.1.2
2018.9.1.1
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-2vh3-cj9j-mcj5
May 15, 2024
eZ Publish Legacy Cross-site Scripting (XSS) in 'disabled module' error template
Medium
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy via the LegacyBridge. Installations where all modules are disabled may be vulnerable to XSS injection in the module name. This is a rare configuration, but we still recommend installing the update, which adds the necessary input washing. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/4697bff700e8cf95d5847ea19dad3479a77b02d9 Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
+ 38 more Show less
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
Fixed in
5.3.12.5
5.4.12.2
2017.12.4.2
2018.6.1.3
2018.9.1.2
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-82rv-45pc-v28w
May 15, 2024
eZ Publish Legacy Patch EZSA-2018-001 for Several vulnerabilities
High
This security advisory fixes 4 separate vulnerabilities in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy by itself or via the LegacyBridge. First, it increases the randomness, and thus the security, of the pseudo-random bytes used to generate a hash for the "forgot password" feature. This protects accounts against being taken over through attacks trying to predict the hash. If the increased randomness is not available in your PHP installation, it will now log a warning. Second, it improves security of the information collector feature, by ensuring no collection emails will be sent from invalid manipulated forms. Third, it stops the possible leaking of the names of content objects that should not be readable for certain users, on installations where these users can create or edit XML text. Fourth, it protects against cross-site scripting (XSS) in the Matrix data type, on installations where users are allowed to edit content classes / content types. We recommend that you install the security update as soon as possible. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezpublish-legacy/commit/917711eb7ffe2b52a3e9fe12505f6810a63696f7 https://github.com/ezsystems/ezpublish-legacy/commit/6db0e6b7739481f27d954548388bd3f0ed2c6fdd https://github.com/ezsystems/ezpublish-legacy/commit/efcd2b61b15eaaf74e0ff28d6c723cf28e655dab https://github.com/ezsystems/ezpublish-legacy/commit/f9ffaf590b63b4f552142cfd4441afbbfb3f19b1 Affected versions
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
+ 24 more Show less
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
Fixed in
5.3.12.3
5.4.11.3
2017.12.2.1
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-10806
GHSA-54p5-gxq6-j98g
May 24, 2022
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. Affected versions
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
+ 17 more Show less
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
Fixed in
5.4.14.1
2017.12.7.2
2019.03.4.2
References Updated Dec 08, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2017.10.1
patch
6 CVEs
GHSA-pqjm-xcp8-wgmm
May 15, 2024
Ez Platform and Legacy are prone to an insecure interpretation of PHP/PHAR uploads
Medium
The eZ Platform and Legacy are affected by an issue related to how uploaded PHP and PHAR files are handled, and consists of two parts: 1. Web server configuration, and 2. Disabling the PHAR stream wrapper. 1. WEB SERVER CONFIGURATION The sample web server configuration in our documentation can in some cases allow the execution of uploaded PHP/PHAR code. This can be abused to allow priviledge escalation and breach of content access controls, among other things. Please ensure that your web server will not execute files in directories were files may be uploaded, such as web/var/ and ezpublish_legacy/var/ As an example, here is how you can make Apache return HTTP 403 Forbidden for a number of executable file types in your eZ Platform var directory. Please adapt it to your needs. It is then possible to enable logging of HTTP 403 in a separate log file if you wish, you could do this to see if someone is trying to abuse the server.
Here is the same configuration, but for the Nginx web server:
2. DISABLE PHAR STREAM WRAPPER PHAR archives may be crafted such that its stream wrapper will execute them without being specifically asked to. With such files, any PHP file operation may cause deserialisation and execution. This may happen even if the file name suffix isn't ".phar". Any site that allows file uploads is at risk. Normally eZ Platform has no need for PHAR support. It's only used by Composer, and that is executed separately from eZ Platform. So one way to avoid this vulnerability is to disable the PHAR stream wrapper within eZ Platform. (If you know you need PHAR support, please consider other means to deal with this vulnerability. For example, enabling the wrapper only in those scripts/bundles that have to deal with such files.) Disabling the stream wrapper should be done in: eZ Platform (web/app.php) CLI scripts (bin/console) Legacy (index.php and CLI scripts) To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezplatform/commit/9a0c52dc4535e4b3ce379f80222dc53f705a2cfd https://github.com/ezsystems/ezpublish-legacy/commit/d21957bf202b091ab39dfb5be300f6c30be3933e Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
2013.04.0
v2013.05.0
v2013.06.0
+ 41 more Show less
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
Fixed in
5.3.12.6
5.4.12.3
2017.12.4.3
2018.6.1.4
2018.9.1.3
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-p9mp-vq4v-v5m5
May 15, 2024
eZ Publish Legacy Passwordless login for LDAP users
High
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy. Installations that are using the legacy LDAP login handler or the TextFile login handler in combination with the standard legacy login handler, may in rare cases be vulnerable to a failure of the standard login handler to verify passwords correctly, allowing unauthorised access. If your installation has never used the LDAP or TextFile login handlers, or never used legacy login at all, then it is not affected. Still, we recommend installing the update, to be on the safe side. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/13f03a2be6c0ee4d0caaafaef05904ea9b0c4d9d Affected versions
v2018.09.0
v2018.09.1
v2018.06.0
v2018.06.1
v2018.06.1.1
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
+ 35 more Show less
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
Fixed in
5.3.12.4
5.4.12.1
2017.12.4.1
2018.6.1.2
2018.9.1.1
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-2vh3-cj9j-mcj5
May 15, 2024
eZ Publish Legacy Cross-site Scripting (XSS) in 'disabled module' error template
Medium
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy via the LegacyBridge. Installations where all modules are disabled may be vulnerable to XSS injection in the module name. This is a rare configuration, but we still recommend installing the update, which adds the necessary input washing. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/4697bff700e8cf95d5847ea19dad3479a77b02d9 Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
+ 38 more Show less
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
Fixed in
5.3.12.5
5.4.12.2
2017.12.4.2
2018.6.1.3
2018.9.1.2
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-82rv-45pc-v28w
May 15, 2024
eZ Publish Legacy Patch EZSA-2018-001 for Several vulnerabilities
High
This security advisory fixes 4 separate vulnerabilities in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy by itself or via the LegacyBridge. First, it increases the randomness, and thus the security, of the pseudo-random bytes used to generate a hash for the "forgot password" feature. This protects accounts against being taken over through attacks trying to predict the hash. If the increased randomness is not available in your PHP installation, it will now log a warning. Second, it improves security of the information collector feature, by ensuring no collection emails will be sent from invalid manipulated forms. Third, it stops the possible leaking of the names of content objects that should not be readable for certain users, on installations where these users can create or edit XML text. Fourth, it protects against cross-site scripting (XSS) in the Matrix data type, on installations where users are allowed to edit content classes / content types. We recommend that you install the security update as soon as possible. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezpublish-legacy/commit/917711eb7ffe2b52a3e9fe12505f6810a63696f7 https://github.com/ezsystems/ezpublish-legacy/commit/6db0e6b7739481f27d954548388bd3f0ed2c6fdd https://github.com/ezsystems/ezpublish-legacy/commit/efcd2b61b15eaaf74e0ff28d6c723cf28e655dab https://github.com/ezsystems/ezpublish-legacy/commit/f9ffaf590b63b4f552142cfd4441afbbfb3f19b1 Affected versions
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
+ 24 more Show less
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
Fixed in
5.3.12.3
5.4.11.3
2017.12.2.1
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-10806
GHSA-54p5-gxq6-j98g
May 24, 2022
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. Affected versions
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
+ 17 more Show less
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
Fixed in
5.4.14.1
2017.12.7.2
2019.03.4.2
References Updated Dec 08, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2017.10.0
minor
6 CVEs
GHSA-pqjm-xcp8-wgmm
May 15, 2024
Ez Platform and Legacy are prone to an insecure interpretation of PHP/PHAR uploads
Medium
The eZ Platform and Legacy are affected by an issue related to how uploaded PHP and PHAR files are handled, and consists of two parts: 1. Web server configuration, and 2. Disabling the PHAR stream wrapper. 1. WEB SERVER CONFIGURATION The sample web server configuration in our documentation can in some cases allow the execution of uploaded PHP/PHAR code. This can be abused to allow priviledge escalation and breach of content access controls, among other things. Please ensure that your web server will not execute files in directories were files may be uploaded, such as web/var/ and ezpublish_legacy/var/ As an example, here is how you can make Apache return HTTP 403 Forbidden for a number of executable file types in your eZ Platform var directory. Please adapt it to your needs. It is then possible to enable logging of HTTP 403 in a separate log file if you wish, you could do this to see if someone is trying to abuse the server.
Here is the same configuration, but for the Nginx web server:
2. DISABLE PHAR STREAM WRAPPER PHAR archives may be crafted such that its stream wrapper will execute them without being specifically asked to. With such files, any PHP file operation may cause deserialisation and execution. This may happen even if the file name suffix isn't ".phar". Any site that allows file uploads is at risk. Normally eZ Platform has no need for PHAR support. It's only used by Composer, and that is executed separately from eZ Platform. So one way to avoid this vulnerability is to disable the PHAR stream wrapper within eZ Platform. (If you know you need PHAR support, please consider other means to deal with this vulnerability. For example, enabling the wrapper only in those scripts/bundles that have to deal with such files.) Disabling the stream wrapper should be done in: eZ Platform (web/app.php) CLI scripts (bin/console) Legacy (index.php and CLI scripts) To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezplatform/commit/9a0c52dc4535e4b3ce379f80222dc53f705a2cfd https://github.com/ezsystems/ezpublish-legacy/commit/d21957bf202b091ab39dfb5be300f6c30be3933e Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
2013.04.0
v2013.05.0
v2013.06.0
+ 41 more Show less
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
Fixed in
5.3.12.6
5.4.12.3
2017.12.4.3
2018.6.1.4
2018.9.1.3
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-p9mp-vq4v-v5m5
May 15, 2024
eZ Publish Legacy Passwordless login for LDAP users
High
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy. Installations that are using the legacy LDAP login handler or the TextFile login handler in combination with the standard legacy login handler, may in rare cases be vulnerable to a failure of the standard login handler to verify passwords correctly, allowing unauthorised access. If your installation has never used the LDAP or TextFile login handlers, or never used legacy login at all, then it is not affected. Still, we recommend installing the update, to be on the safe side. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/13f03a2be6c0ee4d0caaafaef05904ea9b0c4d9d Affected versions
v2018.09.0
v2018.09.1
v2018.06.0
v2018.06.1
v2018.06.1.1
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
+ 35 more Show less
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
Fixed in
5.3.12.4
5.4.12.1
2017.12.4.1
2018.6.1.2
2018.9.1.1
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-2vh3-cj9j-mcj5
May 15, 2024
eZ Publish Legacy Cross-site Scripting (XSS) in 'disabled module' error template
Medium
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy via the LegacyBridge. Installations where all modules are disabled may be vulnerable to XSS injection in the module name. This is a rare configuration, but we still recommend installing the update, which adds the necessary input washing. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/4697bff700e8cf95d5847ea19dad3479a77b02d9 Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
+ 38 more Show less
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
Fixed in
5.3.12.5
5.4.12.2
2017.12.4.2
2018.6.1.3
2018.9.1.2
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-82rv-45pc-v28w
May 15, 2024
eZ Publish Legacy Patch EZSA-2018-001 for Several vulnerabilities
High
This security advisory fixes 4 separate vulnerabilities in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy by itself or via the LegacyBridge. First, it increases the randomness, and thus the security, of the pseudo-random bytes used to generate a hash for the "forgot password" feature. This protects accounts against being taken over through attacks trying to predict the hash. If the increased randomness is not available in your PHP installation, it will now log a warning. Second, it improves security of the information collector feature, by ensuring no collection emails will be sent from invalid manipulated forms. Third, it stops the possible leaking of the names of content objects that should not be readable for certain users, on installations where these users can create or edit XML text. Fourth, it protects against cross-site scripting (XSS) in the Matrix data type, on installations where users are allowed to edit content classes / content types. We recommend that you install the security update as soon as possible. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezpublish-legacy/commit/917711eb7ffe2b52a3e9fe12505f6810a63696f7 https://github.com/ezsystems/ezpublish-legacy/commit/6db0e6b7739481f27d954548388bd3f0ed2c6fdd https://github.com/ezsystems/ezpublish-legacy/commit/efcd2b61b15eaaf74e0ff28d6c723cf28e655dab https://github.com/ezsystems/ezpublish-legacy/commit/f9ffaf590b63b4f552142cfd4441afbbfb3f19b1 Affected versions
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
+ 24 more Show less
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
Fixed in
5.3.12.3
5.4.11.3
2017.12.2.1
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-10806
GHSA-54p5-gxq6-j98g
May 24, 2022
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. Affected versions
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
+ 17 more Show less
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
Fixed in
5.4.14.1
2017.12.7.2
2019.03.4.2
References Updated Dec 08, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2017.10.0-RC1
pre
6 CVEs
GHSA-pqjm-xcp8-wgmm
May 15, 2024
Ez Platform and Legacy are prone to an insecure interpretation of PHP/PHAR uploads
Medium
The eZ Platform and Legacy are affected by an issue related to how uploaded PHP and PHAR files are handled, and consists of two parts: 1. Web server configuration, and 2. Disabling the PHAR stream wrapper. 1. WEB SERVER CONFIGURATION The sample web server configuration in our documentation can in some cases allow the execution of uploaded PHP/PHAR code. This can be abused to allow priviledge escalation and breach of content access controls, among other things. Please ensure that your web server will not execute files in directories were files may be uploaded, such as web/var/ and ezpublish_legacy/var/ As an example, here is how you can make Apache return HTTP 403 Forbidden for a number of executable file types in your eZ Platform var directory. Please adapt it to your needs. It is then possible to enable logging of HTTP 403 in a separate log file if you wish, you could do this to see if someone is trying to abuse the server.
Here is the same configuration, but for the Nginx web server:
2. DISABLE PHAR STREAM WRAPPER PHAR archives may be crafted such that its stream wrapper will execute them without being specifically asked to. With such files, any PHP file operation may cause deserialisation and execution. This may happen even if the file name suffix isn't ".phar". Any site that allows file uploads is at risk. Normally eZ Platform has no need for PHAR support. It's only used by Composer, and that is executed separately from eZ Platform. So one way to avoid this vulnerability is to disable the PHAR stream wrapper within eZ Platform. (If you know you need PHAR support, please consider other means to deal with this vulnerability. For example, enabling the wrapper only in those scripts/bundles that have to deal with such files.) Disabling the stream wrapper should be done in: eZ Platform (web/app.php) CLI scripts (bin/console) Legacy (index.php and CLI scripts) To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezplatform/commit/9a0c52dc4535e4b3ce379f80222dc53f705a2cfd https://github.com/ezsystems/ezpublish-legacy/commit/d21957bf202b091ab39dfb5be300f6c30be3933e Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
2013.04.0
v2013.05.0
v2013.06.0
+ 41 more Show less
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
Fixed in
5.3.12.6
5.4.12.3
2017.12.4.3
2018.6.1.4
2018.9.1.3
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-p9mp-vq4v-v5m5
May 15, 2024
eZ Publish Legacy Passwordless login for LDAP users
High
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy. Installations that are using the legacy LDAP login handler or the TextFile login handler in combination with the standard legacy login handler, may in rare cases be vulnerable to a failure of the standard login handler to verify passwords correctly, allowing unauthorised access. If your installation has never used the LDAP or TextFile login handlers, or never used legacy login at all, then it is not affected. Still, we recommend installing the update, to be on the safe side. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/13f03a2be6c0ee4d0caaafaef05904ea9b0c4d9d Affected versions
v2018.09.0
v2018.09.1
v2018.06.0
v2018.06.1
v2018.06.1.1
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
+ 35 more Show less
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
Fixed in
5.3.12.4
5.4.12.1
2017.12.4.1
2018.6.1.2
2018.9.1.1
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-2vh3-cj9j-mcj5
May 15, 2024
eZ Publish Legacy Cross-site Scripting (XSS) in 'disabled module' error template
Medium
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy via the LegacyBridge. Installations where all modules are disabled may be vulnerable to XSS injection in the module name. This is a rare configuration, but we still recommend installing the update, which adds the necessary input washing. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/4697bff700e8cf95d5847ea19dad3479a77b02d9 Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
+ 38 more Show less
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
Fixed in
5.3.12.5
5.4.12.2
2017.12.4.2
2018.6.1.3
2018.9.1.2
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-82rv-45pc-v28w
May 15, 2024
eZ Publish Legacy Patch EZSA-2018-001 for Several vulnerabilities
High
This security advisory fixes 4 separate vulnerabilities in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy by itself or via the LegacyBridge. First, it increases the randomness, and thus the security, of the pseudo-random bytes used to generate a hash for the "forgot password" feature. This protects accounts against being taken over through attacks trying to predict the hash. If the increased randomness is not available in your PHP installation, it will now log a warning. Second, it improves security of the information collector feature, by ensuring no collection emails will be sent from invalid manipulated forms. Third, it stops the possible leaking of the names of content objects that should not be readable for certain users, on installations where these users can create or edit XML text. Fourth, it protects against cross-site scripting (XSS) in the Matrix data type, on installations where users are allowed to edit content classes / content types. We recommend that you install the security update as soon as possible. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezpublish-legacy/commit/917711eb7ffe2b52a3e9fe12505f6810a63696f7 https://github.com/ezsystems/ezpublish-legacy/commit/6db0e6b7739481f27d954548388bd3f0ed2c6fdd https://github.com/ezsystems/ezpublish-legacy/commit/efcd2b61b15eaaf74e0ff28d6c723cf28e655dab https://github.com/ezsystems/ezpublish-legacy/commit/f9ffaf590b63b4f552142cfd4441afbbfb3f19b1 Affected versions
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
+ 24 more Show less
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
Fixed in
5.3.12.3
5.4.11.3
2017.12.2.1
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-10806
GHSA-54p5-gxq6-j98g
May 24, 2022
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. Affected versions
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
+ 17 more Show less
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
Fixed in
5.4.14.1
2017.12.7.2
2019.03.4.2
References Updated Dec 08, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev | ||
v2017.08.1.1
patch
6 CVEs
GHSA-pqjm-xcp8-wgmm
May 15, 2024
Ez Platform and Legacy are prone to an insecure interpretation of PHP/PHAR uploads
Medium
The eZ Platform and Legacy are affected by an issue related to how uploaded PHP and PHAR files are handled, and consists of two parts: 1. Web server configuration, and 2. Disabling the PHAR stream wrapper. 1. WEB SERVER CONFIGURATION The sample web server configuration in our documentation can in some cases allow the execution of uploaded PHP/PHAR code. This can be abused to allow priviledge escalation and breach of content access controls, among other things. Please ensure that your web server will not execute files in directories were files may be uploaded, such as web/var/ and ezpublish_legacy/var/ As an example, here is how you can make Apache return HTTP 403 Forbidden for a number of executable file types in your eZ Platform var directory. Please adapt it to your needs. It is then possible to enable logging of HTTP 403 in a separate log file if you wish, you could do this to see if someone is trying to abuse the server.
Here is the same configuration, but for the Nginx web server:
2. DISABLE PHAR STREAM WRAPPER PHAR archives may be crafted such that its stream wrapper will execute them without being specifically asked to. With such files, any PHP file operation may cause deserialisation and execution. This may happen even if the file name suffix isn't ".phar". Any site that allows file uploads is at risk. Normally eZ Platform has no need for PHAR support. It's only used by Composer, and that is executed separately from eZ Platform. So one way to avoid this vulnerability is to disable the PHAR stream wrapper within eZ Platform. (If you know you need PHAR support, please consider other means to deal with this vulnerability. For example, enabling the wrapper only in those scripts/bundles that have to deal with such files.) Disabling the stream wrapper should be done in: eZ Platform (web/app.php) CLI scripts (bin/console) Legacy (index.php and CLI scripts) To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezplatform/commit/9a0c52dc4535e4b3ce379f80222dc53f705a2cfd https://github.com/ezsystems/ezpublish-legacy/commit/d21957bf202b091ab39dfb5be300f6c30be3933e Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
2013.04.0
v2013.05.0
v2013.06.0
+ 41 more Show less
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
Fixed in
5.3.12.6
5.4.12.3
2017.12.4.3
2018.6.1.4
2018.9.1.3
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-p9mp-vq4v-v5m5
May 15, 2024
eZ Publish Legacy Passwordless login for LDAP users
High
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy. Installations that are using the legacy LDAP login handler or the TextFile login handler in combination with the standard legacy login handler, may in rare cases be vulnerable to a failure of the standard login handler to verify passwords correctly, allowing unauthorised access. If your installation has never used the LDAP or TextFile login handlers, or never used legacy login at all, then it is not affected. Still, we recommend installing the update, to be on the safe side. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/13f03a2be6c0ee4d0caaafaef05904ea9b0c4d9d Affected versions
v2018.09.0
v2018.09.1
v2018.06.0
v2018.06.1
v2018.06.1.1
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
+ 35 more Show less
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
Fixed in
5.3.12.4
5.4.12.1
2017.12.4.1
2018.6.1.2
2018.9.1.1
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-2vh3-cj9j-mcj5
May 15, 2024
eZ Publish Legacy Cross-site Scripting (XSS) in 'disabled module' error template
Medium
This security advisory fixes a vulnerability in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy via the LegacyBridge. Installations where all modules are disabled may be vulnerable to XSS injection in the module name. This is a rare configuration, but we still recommend installing the update, which adds the necessary input washing. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply this patch manually: https://github.com/ezsystems/ezpublish-legacy/commit/4697bff700e8cf95d5847ea19dad3479a77b02d9 Affected versions
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
+ 38 more Show less
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
Fixed in
5.3.12.5
5.4.12.2
2017.12.4.2
2018.6.1.3
2018.9.1.2
References
Updated Nov 29, 2024 · Source: OSV.dev
GHSA-82rv-45pc-v28w
May 15, 2024
eZ Publish Legacy Patch EZSA-2018-001 for Several vulnerabilities
High
This security advisory fixes 4 separate vulnerabilities in eZ Publish Legacy, and we recommend that you install it as soon as possible if you are using Legacy by itself or via the LegacyBridge. First, it increases the randomness, and thus the security, of the pseudo-random bytes used to generate a hash for the "forgot password" feature. This protects accounts against being taken over through attacks trying to predict the hash. If the increased randomness is not available in your PHP installation, it will now log a warning. Second, it improves security of the information collector feature, by ensuring no collection emails will be sent from invalid manipulated forms. Third, it stops the possible leaking of the names of content objects that should not be readable for certain users, on installations where these users can create or edit XML text. Fourth, it protects against cross-site scripting (XSS) in the Matrix data type, on installations where users are allowed to edit content classes / content types. We recommend that you install the security update as soon as possible. To install, use Composer to update to one of the "Resolving versions" mentioned above, or apply these patches manually: https://github.com/ezsystems/ezpublish-legacy/commit/917711eb7ffe2b52a3e9fe12505f6810a63696f7 https://github.com/ezsystems/ezpublish-legacy/commit/6db0e6b7739481f27d954548388bd3f0ed2c6fdd https://github.com/ezsystems/ezpublish-legacy/commit/efcd2b61b15eaaf74e0ff28d6c723cf28e655dab https://github.com/ezsystems/ezpublish-legacy/commit/f9ffaf590b63b4f552142cfd4441afbbfb3f19b1 Affected versions
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
+ 24 more Show less
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
Fixed in
5.3.12.3
5.4.11.3
2017.12.2.1
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-10806
GHSA-54p5-gxq6-j98g
May 24, 2022
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution. Affected versions
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
+ 17 more Show less
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
Fixed in
5.4.14.1
2017.12.7.2
2019.03.4.2
References Updated Dec 08, 2024 · Source: OSV.dev
GHSA-jpwx-ffjq-wr4w
Sep 07, 2021
Content object state fetch functions open to SQL injection
High
ImpactThis Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible. PatchesThe fix is distributed via Composer, see "Patched versions". Affected versions
v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
+ 64 more Show less
v2018.09.3
v2018.09.4
v2018.09.5
v2019.03.0
v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6
2013.04.0
v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11
v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2
v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3
v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0
v2017.10.0-RC1
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3
Fixed in
2017.12.7.4
2019.03.6.1
References
Updated Dec 02, 2024 · Source: OSV.dev |
v2017.08.1.1
patch
Dependencies (30)
+ 22 more
Changelog
Compare changes
|