Vulnerability Description
An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibexa | Digital Experience Platform | >= 3.3.0, < 3.3.18 |
| Ibexa | Ezplatform-Http-Cache-Fastly | >= 1.1.0, < 1.1.9 |
| Ibexa | Fastly | >= 4.0.0, < 4.0.5 |
| Ibexa | Ez Platform Kernel | >= 1.3.0, < 1.3.17 |
| Ibexa | Kernel | >= 4.0.0, < 4.0.7 |
Related Weaknesses (CWE)
References
- https://developers.ibexa.co/security-advisories/ibexa-sa-2022-004-ineffective-obVendor Advisory
- https://github.com/ezsystems/ezpublish-kernel/security/advisories/GHSA-5x4f-7xgqVendor Advisory
- https://developers.ibexa.co/security-advisories/ibexa-sa-2022-004-ineffective-obVendor Advisory
- https://github.com/ezsystems/ezpublish-kernel/security/advisories/GHSA-5x4f-7xgqVendor Advisory
FAQ
What is CVE-2022-48367?
CVE-2022-48367 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled.
How severe is CVE-2022-48367?
CVE-2022-48367 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-48367?
Check the references section above for vendor advisories and patch information. Affected products include: Ibexa Digital Experience Platform, Ibexa Ezplatform-Http-Cache-Fastly, Ibexa Fastly, Ibexa Ez Platform Kernel, Ibexa Kernel.