CVE-2024-27915

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-27915
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-27915.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-27915
Aliases
Published
2024-03-06T19:33:11.798Z
Modified
2025-12-05T04:15:41.616995Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Sulu grants access to pages regardless of role permissions
Details

Sulu is a PHP content management system. Starting in verson 2.2.0 and prior to version 2.4.17 and 2.5.13, access to pages is granted regardless of role permissions for webspaces which have a security system configured and permission check enabled. Webspaces without do not have this issue. The problem is patched in versions 2.4.17 and 2.5.13. Some workarounds are available. One may apply the patch to vendor/symfony/security-http/HttpUtils.php manually or avoid installing symfony/security-http versions greater equal than v5.4.30 or v6.3.6.

Database specific
{
    "cwe_ids": [
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/27xxx/CVE-2024-27915.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/sulu/sulu

Affected ranges

Type
GIT
Repo
https://github.com/sulu/sulu
Events
Database specific
{
    "versions": [
        {
            "introduced": "2.2.0"
        },
        {
            "fixed": "2.4.17"
        }
    ]
}
Type
GIT
Repo
https://github.com/sulu/sulu
Events
Database specific
{
    "versions": [
        {
            "introduced": "2.5.0-alpha1"
        },
        {
            "fixed": "2.5.13"
        }
    ]
}

Affected versions

1.*

1.6.37
1.6.38
1.6.39
1.6.40
1.6.41
1.6.42
1.6.43
1.6.44
1.6.45

2.*

2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.15
2.2.16
2.2.17
2.2.18
2.2.19
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0-RC1
2.3.0-RC2
2.3.1
2.3.10
2.3.11
2.3.12
2.3.13
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.0-RC1
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.16
2.4.17
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.0-alpha1
2.5.1
2.5.10
2.5.11
2.5.12
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9