GHSA-jpwx-ffjq-wr4w

Suggest an improvement
Source
https://github.com/advisories/GHSA-jpwx-ffjq-wr4w
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/09/GHSA-jpwx-ffjq-wr4w/GHSA-jpwx-ffjq-wr4w.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jpwx-ffjq-wr4w
Published
2021-09-07T22:54:23Z
Modified
2024-12-02T05:54:42.708773Z
Summary
Content object state fetch functions open to SQL injection
Details

Impact

This Security Update is about a vulnerability in eZ Publish Legacy. The content object state code could be vulnerable to SQL injection. There is no known exploit, but one might be possible. If you use Legacy in any way, we strongly recommend that you install this update as soon as possible.

Patches

The fix is distributed via Composer, see "Patched versions".

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [
        "CWE-89"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2021-09-03T20:10:38Z"
}
References

Affected packages

Packagist / ezsystems/ezpublish-legacy

Package

Name
ezsystems/ezpublish-legacy
Purl
pkg:composer/ezsystems/ezpublish-legacy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2018.06.0
Fixed
2019.03.6.1

Affected versions

v2018.*

v2018.06.0
v2018.06.1
v2018.06.1.1
v2018.06.1.2
v2018.06.1.3
v2018.06.1.4
v2018.09.0
v2018.09.1
v2018.09.1.1
v2018.09.1.2
v2018.09.1.3
v2018.09.2
v2018.09.3
v2018.09.4
v2018.09.5

v2019.*

v2019.03.0-rc1
v2019.03.0-rc2
v2019.03.0
v2019.03.1
v2019.03.2
v2019.03.3
v2019.03.4
v2019.03.4.2
v2019.03.5
v2019.03.5.1
v2019.03.6

Database specific

{
    "last_known_affected_version_range": "<= 2019.03.5.1"
}

Packagist / ezsystems/ezpublish-legacy

Package

Name
ezsystems/ezpublish-legacy
Purl
pkg:composer/ezsystems/ezpublish-legacy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2017.12.7.4

Affected versions

2013.*

2013.04.0

v2013.*

v2013.05.0
v2013.06.0
v2013.07.0
v2013.07.1
v2013.07.3
v2013.09.0
v2013.11

v2014.*

v2014.01.0
v2014.01.1
v2014.01.2
v2014.03.1
v2014.03.2
v2014.05.0
v2014.05.1
v2014.05.2
v2014.07.0
v2014.07.1
v2014.07.2
v2014.11.0
v2014.11.1
v2014.11.2

v2015.*

v2015.01.0
v2015.01.1
v2015.01.2
v2015.01.3

v2017.*

v2017.08.0
v2017.08.1
v2017.08.1.1
v2017.10.0-RC1
v2017.10.0
v2017.10.1
v2017.12.0
v2017.12.1
v2017.12.1.1
v2017.12.2
v2017.12.2.1
v2017.12.2.2
v2017.12.3
v2017.12.3.1
v2017.12.3.2
v2017.12.4
v2017.12.4.1
v2017.12.4.2
v2017.12.4.3
v2017.12.5
v2017.12.6
v2017.12.7
v2017.12.7.2
v2017.12.7.3

Database specific

{
    "last_known_affected_version_range": "<= 2017.12.7.3"
}