{"id":"GHSA-m2v2-8227-59f5","summary":"Exposure of sensitive information in concrete5/core","details":"In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowed to Add Message to a Conversation.To remediate this, a check was added to verify a user has permissions to view files before attaching the files to a message in \"add / edit message”.","aliases":["CVE-2021-22967"],"modified":"2024-12-02T05:44:57.907818Z","published":"2021-11-23T17:54:39Z","database_specific":{"nvd_published_at":"2021-11-19T19:15:00Z","cwe_ids":["CWE-200","CWE-639"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-11-22T19:40:20Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-22967"},{"type":"WEB","url":"https://hackerone.com/reports/869612"},{"type":"WEB","url":"https://documentation.concretecms.org/developers/introduction/version-history/857-release-notes"}],"affected":[{"package":{"name":"concrete5/core","ecosystem":"Packagist","purl":"pkg:composer/concrete5/core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.5.7"}]}],"versions":["8.2.0","8.2.0RC2","8.2.1","8.3.0","8.3.1","8.3.2","8.4.0","8.4.0RC3","8.4.0RC4","8.4.1","8.4.2","8.4.3","8.4.4","8.4.5","8.5.0","8.5.0RC1","8.5.0RC2","8.5.1","8.5.2","8.5.3","8.5.4","8.5.5","8.5.6","8.5.6RC1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/11/GHSA-m2v2-8227-59f5/GHSA-m2v2-8227-59f5.json"}}],"schema_version":"1.9.0"}