{"id":"GHSA-44m4-9cjp-j587","aliases":[],"url":"https://o3.security/vulnerability/GHSA-44m4-9cjp-j587","summary":"IBX-1392: Image filenames sanitization","details":"ezsystems/ezpublish-kernel versions 7.5.* before 7.5.26 are vulnerable to certain injection attacks and unauthorized access to some image files.","published":"2022-01-21T23:24:14Z","modified":"2024-12-04T05:42:04.230003Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"ezsystems/ezpublish-kernel","fixedVersion":"7.5.26"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/ezsystems/ezpublish-kernel/security/advisories/GHSA-44m4-9cjp-j587"},{"type":"WEB","url":"https://developers.ibexa.co/security-advisories/ibexa-sa-2022-001-image-filenames-sanitization"},{"type":"WEB","url":"https://github.com/ezsystems/ezpublish-kernel"},{"type":"WEB","url":"https://github.com/ezsystems/ezpublish-kernel/releases/tag/v7.5.26"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-04T05:42:04.230003Z"}}