{"id":"GHSA-hq76-662x-7mw4","aliases":[],"url":"https://o3.security/vulnerability/GHSA-hq76-662x-7mw4","summary":"Pimcore includes vulnerable PHPOffice/PhpSpreadsheet","details":"### Summary\nPimcore 10.6.x and Enterprise 10.6.x versions currently depend on PHPOffice/PhpSpreadsheet version 1.x, which has recently been identified with a security vulnerability (CVE-2024-45048). To mitigate this issue, it is recommended to update to the latest version 2.2.2. For more details, please refer to the official advisory: [GHSA-ghg6-32f9-2jp7](https://github.com/advisories/GHSA-ghg6-32f9-2jp7).\n\n","published":"2024-09-03T19:45:26Z","modified":"2024-12-05T05:28:51.120085Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"pimcore/data-importer","fixedVersion":"1.8.9"},{"ecosystem":"Packagist","name":"pimcore/data-importer","fixedVersion":"1.9.3"},{"ecosystem":"Packagist","name":"pimcore/admin-ui-classic-bundle","fixedVersion":"1.3.11"},{"ecosystem":"Packagist","name":"pimcore/admin-ui-classic-bundle","fixedVersion":"1.4.7"},{"ecosystem":"Packagist","name":"pimcore/admin-ui-classic-bundle","fixedVersion":"1.5.4"},{"ecosystem":"Packagist","name":"pimcore/pimcore","fixedVersion":"10.6.9.12"},{"ecosystem":"Packagist","name":"pimcore/pimcore","fixedVersion":"11.1.6.11"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/pimcore/pimcore/security/advisories/GHSA-hq76-662x-7mw4"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-ghg6-32f9-2jp7"},{"type":"PACKAGE","url":"https://github.com/pimcore/pimcore"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-05T05:28:51.120085Z"}}