Go back

Ibexa Kernel for eZ Platform ignoring object state limitation policy granting access to certain links

severity
critical
date
Affecting
  • ezpublish-kernel versions 7.5.0 upto 7.5.28

CVE
CVE-2022-48367
CVE type
Improper Preservation of Permissions
CVSS
6.8
CVSS V3 Vector
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N