CVE-2022-41876

Source
https://cve.org/CVERecord?id=CVE-2022-41876
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-41876.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-41876
Aliases
Published
2022-11-10T00:00:00Z
Modified
2026-04-10T04:51:51.673038Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
ezplatform-graphql GraphQL queries can expose password hashes
Details

ezplatform-graphql is a GraphQL server implementation for Ibexa DXP and Ibexa Open Source. Versions prior to 2.3.12 and 1.0.13 are subject to Insecure Storage of Sensitive Information. Unauthenticated GraphQL queries for user accounts can expose password hashes of users that have created or modified content, typically administrators and editors. This issue has been patched in versions 2.3.12, and 1.0.13 on the 1.X branch. Users unable to upgrade can remove the "passwordHash" entry from "src/bundle/Resources/config/graphql/User.types.yaml" in the GraphQL package, and other properties like hash type, email, login if you prefer.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-200",
        "CWE-922"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/41xxx/CVE-2022-41876.json"
}
References

Affected packages

Git / github.com/ezsystems/ezplatform-graphql

Affected ranges

Type
GIT
Repo
https://github.com/ezsystems/ezplatform-graphql
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.0.13"
        }
    ]
}
Type
GIT
Repo
https://github.com/ezsystems/ezplatform-graphql
Events
Database specific
{
    "versions": [
        {
            "introduced": "v2.0.0-beta1"
        },
        {
            "fixed": "2.3.12"
        }
    ]
}

Affected versions

v0.*
v0.3.0
v0.3.1
v0.3.2
v0.3.3
v0.4.0-beta3
v1.*
v1.0.0
v1.0.0-rc2
v1.0.0-rc3
v1.0.1
v1.0.2
v1.0.3
v1.0.4-rc1
v1.0.5
v1.0.6
v1.0.6-rc1
v1.0.7
v1.0.8
v1.0.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-41876.json"