{"id":"GHSA-2w9p-xxqr-h253","aliases":[],"url":"https://o3.security/vulnerability/GHSA-2w9p-xxqr-h253","summary":"eZ Platform Object Injection in SiteAccessMatchListener","details":"This Security Advisory is about an object injection vulnerability in the SiteAccessMatchListener of eZ Platform, which could lead to remote code execution (RCE), a very serious threat. All sites may be affected.\n\nUpdate: There are bugs introduced by this fix, particularly but not limited to compound siteaccess matchers. These have been fixed in ezsystems/ezplatform-kernel v1.0.3, and in ezsystems/ezpublish-kernel v7.5.8, v6.13.6.4, and v5.4.15.","published":"2024-05-15T21:14:18Z","modified":"2024-11-29T05:40:05.054112Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"ezsystems/ezplatform-kernel","fixedVersion":"1.0.3"}],"fix":null,"references":[{"type":"WEB","url":"https://ezplatform.com/security-advisories/ezsa-2020-004-object-injection-in-siteaccessmatchlistener"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/ezsystems/ezplatform-kernel/2020-05-20-1.yaml"},{"type":"PACKAGE","url":"https://github.com/ezsystems/ezplatform-kernel"},{"type":"WEB","url":"https://web.archive.org/web/20201024030303/https://ezplatform.com/security-advisories/ezsa-2020-004-object-injection-in-siteaccessmatchlistener"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-29T05:40:05.054112Z"}}