{"id":"GHSA-64vj-933f-6pm3","summary":"eZ Platform Object Injection in SiteAccessMatchListener","details":"This Security Advisory is about an object injection vulnerability in the SiteAccessMatchListener of eZ Platform, which could lead to remote code execution (RCE), a very serious threat. All sites may be affected.\n\nUpdate: There are bugs introduced by this fix, particularly but not limited to compound siteaccess matchers. These have been fixed in ezsystems/ezplatform-kernel v1.0.3, and in ezsystems/ezpublish-kernel v7.5.8, v6.13.6.4, and v5.4.15.","modified":"2024-11-29T05:40:36.957136Z","published":"2024-05-15T21:28:27Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-94"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-05-15T21:28:27Z"},"references":[{"type":"WEB","url":"https://ezplatform.com/security-advisories/ezsa-2020-004-object-injection-in-siteaccessmatchlistener"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/ezsystems/ezpublish-kernel/2020-05-20-1.yaml"},{"type":"PACKAGE","url":"https://github.com/ezsystems/ezpublish-kernel"}],"affected":[{"package":{"name":"ezsystems/ezpublish-kernel","ecosystem":"Packagist","purl":"pkg:composer/ezsystems/ezpublish-kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.5.0"},{"fixed":"7.5.8"}]}],"versions":["v7.5.0","v7.5.1","v7.5.2","v7.5.3","v7.5.4","v7.5.5","v7.5.6","v7.5.6-rc1","v7.5.6.2","v7.5.7","v7.5.7-rc1","v7.5.7.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-64vj-933f-6pm3/GHSA-64vj-933f-6pm3.json"}},{"package":{"name":"ezsystems/ezpublish-kernel","ecosystem":"Packagist","purl":"pkg:composer/ezsystems/ezpublish-kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.13.6.4"}]}],"versions":["v6.13.0","v6.13.0.1","v6.13.1","v6.13.1-rc1","v6.13.1.1","v6.13.1.2","v6.13.2","v6.13.2-beta1","v6.13.2-rc1","v6.13.3","v6.13.3-beta1","v6.13.3-rc1","v6.13.4","v6.13.4-beta1","v6.13.4-rc1","v6.13.5","v6.13.5.1","v6.13.6","v6.13.6-rc1","v6.13.6.2","v6.13.6.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-64vj-933f-6pm3/GHSA-64vj-933f-6pm3.json"}},{"package":{"name":"ezsystems/ezpublish-kernel","ecosystem":"Packagist","purl":"pkg:composer/ezsystems/ezpublish-kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.4.0"},{"fixed":"5.4.15"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-64vj-933f-6pm3/GHSA-64vj-933f-6pm3.json"}}],"schema_version":"1.9.0"}