Security vulnerability in Sulu versions 2.2.0 to 2.5.13
CVE-2024-27915

6.8MEDIUM

Key Information:

Vendor

Sulu

Status
Vendor
CVE Published:
6 March 2024

What is CVE-2024-27915?

In Sulu, a PHP content management system, a vulnerability exists that allows access to web pages without respecting role permissions for specific webspaces where a security system is enabled and permission checks are active. This issue impacts Sulu versions from 2.2.0 to 2.4.17 and 2.5.13, while it does not affect webspaces lacking a security configuration. The vulnerability can be mitigated by patching to versions 2.4.17 and 2.5.13. Alternatively, users can apply a manual patch to vendor/symfony/security-http/HttpUtils.php or refrain from using symfony/security-http versions equal to or above v5.4.30 or v6.3.6.

Affected Version(s)

sulu >= 2.2.0, < 2.4.17 < 2.2.0, 2.4.17

sulu >= 2.5.0-alpha1, < 2.5.13 < 2.5.0-alpha1, 2.5.13

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.