{"id":"GHSA-64vj-933f-6pm3","aliases":[],"url":"https://o3.security/vulnerability/GHSA-64vj-933f-6pm3","summary":"eZ Platform Object Injection in SiteAccessMatchListener","details":"This Security Advisory is about an object injection vulnerability in the SiteAccessMatchListener of eZ Platform, which could lead to remote code execution (RCE), a very serious threat. All sites may be affected.\n\nUpdate: There are bugs introduced by this fix, particularly but not limited to compound siteaccess matchers. These have been fixed in ezsystems/ezplatform-kernel v1.0.3, and in ezsystems/ezpublish-kernel v7.5.8, v6.13.6.4, and v5.4.15.","published":"2024-05-15T21:28:27Z","modified":"2024-11-29T05:40:36.957136Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"ezsystems/ezpublish-kernel","fixedVersion":"7.5.8"},{"ecosystem":"Packagist","name":"ezsystems/ezpublish-kernel","fixedVersion":"6.13.6.4"},{"ecosystem":"Packagist","name":"ezsystems/ezpublish-kernel","fixedVersion":"5.4.15"}],"fix":null,"references":[{"type":"WEB","url":"https://ezplatform.com/security-advisories/ezsa-2020-004-object-injection-in-siteaccessmatchlistener"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/ezsystems/ezpublish-kernel/2020-05-20-1.yaml"},{"type":"PACKAGE","url":"https://github.com/ezsystems/ezpublish-kernel"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-29T05:40:36.957136Z"}}