GHSA-cchp-3rq6-69wj

Suggest an improvement
Source
https://github.com/advisories/GHSA-cchp-3rq6-69wj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-cchp-3rq6-69wj/GHSA-cchp-3rq6-69wj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-cchp-3rq6-69wj
Aliases
  • CVE-2024-38874
Published
2024-06-21T09:30:26Z
Modified
2024-06-25T02:34:56.683276Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L CVSS Calculator
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
events2 TYPO3 extension insecure direct object reference (IDOR) vulnerability
Details

An issue was discovered in the events2 (aka Events 2) extension before 8.3.8 and 9.x before 9.0.6 for TYPO3. Missing access checks in the management plugin lead to an insecure direct object reference (IDOR) vulnerability with the potential to activate or delete various events for unauthenticated users.

Database specific
{
    "nvd_published_at": "2024-06-21T07:15:10Z",
    "cwe_ids": [
        "CWE-639"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-06-21T15:07:37Z"
}
References

Affected packages

Packagist / jweiland/events2

Package

Name
jweiland/events2
Purl
pkg:composer/jweiland/events2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.3.8

Affected versions

1.*

1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5

2.*

2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.2
2.2.3
2.2.5
2.2.6
2.2.7
2.2.8
2.3.0
2.3.1

3.*

3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.1.0
3.1.1
3.1.2
3.2.0
3.2.2
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.7.0
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.8.1
3.8.2
3.8.3
3.8.4
3.8.5
3.8.6
3.8.7
3.8.8
3.9.0
3.9.1
3.9.2
3.10.0
3.10.1

4.*

4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.1.3
4.2.0
4.2.1
4.2.2
4.2.3

5.*

5.0.0
5.1.0
5.1.1
5.1.2
5.1.3

6.*

6.0.0
6.1.0
6.1.1
6.1.2
6.2.0
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5
6.3.0
6.3.1
6.3.2
6.3.3
6.3.4

7.*

7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.0.9
7.0.10
7.0.11
7.0.12
7.0.13
7.0.14
7.0.15
7.0.16
7.0.17
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.1.5
7.1.6
7.1.7
7.1.8
7.1.9
7.1.10
7.1.11
7.1.12
7.1.13
7.1.14

8.*

8.0.0
8.0.1
8.1.0
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.2.0
8.2.1
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.3.5
8.3.6
8.3.7

Packagist / jweiland/events2

Package

Name
jweiland/events2
Purl
pkg:composer/jweiland/events2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
9.0.0
Fixed
9.0.6

Affected versions

9.*

9.0.0
9.0.1
9.0.2
9.0.3
9.0.4
9.0.5