{"id":"GHSA-44m4-9cjp-j587","summary":"IBX-1392: Image filenames sanitization","details":"ezsystems/ezpublish-kernel versions 7.5.* before 7.5.26 are vulnerable to certain injection attacks and unauthorized access to some image files.","modified":"2024-12-04T05:42:04.230003Z","published":"2022-01-21T23:24:14Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-01-19T16:14:58Z","nvd_published_at":null,"cwe_ids":[],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/ezsystems/ezpublish-kernel/security/advisories/GHSA-44m4-9cjp-j587"},{"type":"WEB","url":"https://developers.ibexa.co/security-advisories/ibexa-sa-2022-001-image-filenames-sanitization"},{"type":"WEB","url":"https://github.com/ezsystems/ezpublish-kernel"},{"type":"WEB","url":"https://github.com/ezsystems/ezpublish-kernel/releases/tag/v7.5.26"}],"affected":[{"package":{"name":"ezsystems/ezpublish-kernel","ecosystem":"Packagist","purl":"pkg:composer/ezsystems/ezpublish-kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.5.0"},{"fixed":"7.5.26"}]}],"versions":["v7.5.0","v7.5.1","v7.5.10","v7.5.11","v7.5.12","v7.5.13","v7.5.14","v7.5.15","v7.5.15.1","v7.5.15.2","v7.5.16","v7.5.17","v7.5.18","v7.5.19","v7.5.2","v7.5.20","v7.5.21","v7.5.22","v7.5.23","v7.5.24","v7.5.25","v7.5.3","v7.5.4","v7.5.5","v7.5.6","v7.5.6-rc1","v7.5.6.2","v7.5.7","v7.5.7-rc1","v7.5.7.1","v7.5.8","v7.5.9","v7.5.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-44m4-9cjp-j587/GHSA-44m4-9cjp-j587.json"}}],"schema_version":"1.9.0"}