{"id":"GHSA-q8cr-xphm-7gfv","summary":"Akeneo PIM vulnerable to shell injection in the mass edition","details":"Akeneo PIM CE and EE \u003c1.6.6, \u003c1.5.15, \u003c1.4.28 are vulnerable to shell injection in the mass edition, resulting in remote execution.","aliases":["CVE-2017-1000009"],"modified":"2024-04-25T21:57:34.317446Z","published":"2022-05-13T01:24:28Z","database_specific":{"nvd_published_at":"2017-07-17T13:18:00Z","cwe_ids":["CWE-78"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2024-04-25T21:34:47Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000009"},{"type":"PACKAGE","url":"https://github.com/akeneo/pim-community-dev"},{"type":"WEB","url":"https://github.com/akeneo/pim-community-dev/blob/1.5/CHANGELOG-1.5.md#bug-fixes-2"},{"type":"WEB","url":"https://github.com/akeneo/pim-community-dev/blob/master/CHANGELOG-1.4.md#bug-fixes"},{"type":"WEB","url":"https://github.com/akeneo/pim-community-dev/blob/master/CHANGELOG-1.6.md#bug-fixes-2"}],"affected":[{"package":{"name":"akeneo/pim-community-dev","ecosystem":"Packagist","purl":"pkg:composer/akeneo/pim-community-dev"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.4"},{"fixed":"1.4.28"}]}],"versions":["v1.4.0","v1.4.0-ALPHA1","v1.4.0-BETA1","v1.4.0-BETA2","v1.4.0-BETA3","v1.4.0-RC1","v1.4.1","v1.4.10","v1.4.11","v1.4.12","v1.4.13","v1.4.14","v1.4.15","v1.4.16","v1.4.17","v1.4.18","v1.4.19","v1.4.2","v1.4.20","v1.4.21","v1.4.22","v1.4.23","v1.4.24","v1.4.25","v1.4.26","v1.4.27","v1.4.3","v1.4.4","v1.4.5","v1.4.6","v1.4.7","v1.4.8","v1.4.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-q8cr-xphm-7gfv/GHSA-q8cr-xphm-7gfv.json"}},{"package":{"name":"akeneo/pim-community-dev","ecosystem":"Packagist","purl":"pkg:composer/akeneo/pim-community-dev"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.5"},{"fixed":"1.5.15"}]}],"versions":["v1.5.0","v1.5.0-ALPHA1","v1.5.0-BETA1","v1.5.0-RC1","v1.5.1","v1.5.10","v1.5.11","v1.5.12","v1.5.13","v1.5.14","v1.5.2","v1.5.3","v1.5.4","v1.5.5","v1.5.6","v1.5.7","v1.5.8","v1.5.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-q8cr-xphm-7gfv/GHSA-q8cr-xphm-7gfv.json"}},{"package":{"name":"akeneo/pim-community-dev","ecosystem":"Packagist","purl":"pkg:composer/akeneo/pim-community-dev"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.6"},{"fixed":"1.6.6"}]}],"versions":["v1.6.0","v1.6.0-ALPHA1","v1.6.0-ALPHA2","v1.6.0-RC1","v1.6.1","v1.6.2","v1.6.3","v1.6.4","v1.6.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-q8cr-xphm-7gfv/GHSA-q8cr-xphm-7gfv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}