{"id":"GHSA-2w9p-xxqr-h253","summary":"eZ Platform Object Injection in SiteAccessMatchListener","details":"This Security Advisory is about an object injection vulnerability in the SiteAccessMatchListener of eZ Platform, which could lead to remote code execution (RCE), a very serious threat. All sites may be affected.\n\nUpdate: There are bugs introduced by this fix, particularly but not limited to compound siteaccess matchers. These have been fixed in ezsystems/ezplatform-kernel v1.0.3, and in ezsystems/ezpublish-kernel v7.5.8, v6.13.6.4, and v5.4.15.","modified":"2024-11-29T05:40:05.054112Z","published":"2024-05-15T21:14:18Z","database_specific":{"cwe_ids":["CWE-94"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-05-15T21:14:18Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://ezplatform.com/security-advisories/ezsa-2020-004-object-injection-in-siteaccessmatchlistener"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/ezsystems/ezplatform-kernel/2020-05-20-1.yaml"},{"type":"PACKAGE","url":"https://github.com/ezsystems/ezplatform-kernel"},{"type":"WEB","url":"https://web.archive.org/web/20201024030303/https://ezplatform.com/security-advisories/ezsa-2020-004-object-injection-in-siteaccessmatchlistener"}],"affected":[{"package":{"name":"ezsystems/ezplatform-kernel","ecosystem":"Packagist","purl":"pkg:composer/ezsystems/ezplatform-kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"fixed":"1.0.3"}]}],"versions":["v1.0.0","v1.0.1","v1.0.1.1","v1.0.2","v1.0.2.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-2w9p-xxqr-h253/GHSA-2w9p-xxqr-h253.json"}}],"schema_version":"1.9.0"}