{"id":"GHSA-32rx-xvvr-4xv9","aliases":[],"url":"https://o3.security/vulnerability/GHSA-32rx-xvvr-4xv9","summary":"easyadmin-extension-bundle action case insensitivity","details":"In alterphp/easyadmin-extension-bundle, role based access rules do not handle action name case sensitivity which may lead to unauthorized access.","published":"2024-05-15T17:45:51Z","modified":"2024-11-29T05:30:47.362576Z","cvss":{"score":7.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"alterphp/easyadmin-extension-bundle","fixedVersion":"1.3.1"},{"ecosystem":"Packagist","name":"alterphp/easyadmin-extension-bundle","fixedVersion":"1.2.11"}],"fix":{"url":"https://github.com/alterphp/EasyAdminExtensionBundle/commit/68407ca5be644d1c53fb894453df951230afc6dc","label":"alterphp/EasyAdminExtensionBundle@68407ca"},"references":[{"type":"WEB","url":"https://github.com/alterphp/EasyAdminExtensionBundle/commit/68407ca5be644d1c53fb894453df951230afc6dc"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/alterphp/easyadmin-extension-bundle/2018-10-02.yaml"},{"type":"WEB","url":"https://github.com/alterphp/EasyAdminExtensionBundle/releases/tag/v1.3.1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-29T05:30:47.362576Z"}}