CVE-2022-41876

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-41876
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-41876.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-41876
Aliases
Withdrawn
2024-05-15T05:33:30.996769Z
Published
2022-11-10T21:15:10Z
Modified
2023-11-08T04:10:33.464476Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

ezplatform-graphql is a GraphQL server implementation for Ibexa DXP and Ibexa Open Source. Versions prior to 2.3.12 and 1.0.13 are subject to Insecure Storage of Sensitive Information. Unauthenticated GraphQL queries for user accounts can expose password hashes of users that have created or modified content, typically administrators and editors. This issue has been patched in versions 2.3.12, and 1.0.13 on the 1.X branch. Users unable to upgrade can remove the "passwordHash" entry from "src/bundle/Resources/config/graphql/User.types.yaml" in the GraphQL package, and other properties like hash type, email, login if you prefer.

References

Affected packages

Git / github.com/ezsystems/ezplatform

Affected ranges

Type
GIT
Repo
https://github.com/ezsystems/ezplatform
Events
Type
GIT
Repo
https://github.com/ezsystems/ezplatform-graphql
Events