{"id":"CVE-2023-32062","aliases":["GHSA-x2xm-p6vq-482g"],"url":"https://o3.security/vulnerability/CVE-2023-32062","summary":"OroCalendarBundle has incorrect system calendar events visibility","details":"OroPlatform is a package that assists system and user calendar management. Back-office users can access information from any system calendar event, bypassing ACL security restrictions due to insufficient security checks. This vulnerability has been patched in version 5.1.1.","published":"2023-11-27T20:58:35.357Z","modified":"2026-08-12T03:51:46.345048090Z","cvss":{"score":5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"oro/calendar-bundle","fixedVersion":null},{"ecosystem":"Packagist","name":"oro/calendar-bundle","fixedVersion":"5.0.7"},{"ecosystem":"Packagist","name":"oro/calendar-bundle","fixedVersion":"5.1.1"}],"fix":{"url":"https://github.com/oroinc/OroCalendarBundle/commit/460a8ffb63b10c76f2fa26d53512164851c4909b","label":"oroinc/OroCalendarBundle@460a8ff"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/32xxx/CVE-2023-32062.json"},{"type":"ADVISORY","url":"https://github.com/oroinc/crm/security/advisories/GHSA-x2xm-p6vq-482g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-32062"},{"type":"FIX","url":"https://github.com/oroinc/OroCalendarBundle/commit/460a8ffb63b10c76f2fa26d53512164851c4909b"},{"type":"FIX","url":"https://github.com/oroinc/OroCalendarBundle/commit/5f4734aa02088191c1c1d90ac0909f48610fe531"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:46.345048090Z"}}