GHSA-wr3c-6c22-m9v6 – typo3/neos
Package
Manager: composer
Name: typo3/neos
Vulnerable Version: >=1.1.0 <1.1.3 || >=1.2.0 <1.2.3
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
EPSS: N/A pctlN/A
Details
Privilege Escalation in TYPO3 Neos It has been discovered that TYPO3 Neos is vulnerable to Privilege Escalation. Logged in editors could access, create and modify content nodes that exist in the workspace of other editors.
Metadata
Created: 2024-06-05T17:28:04Z
Modified: 2024-06-05T17:28:04Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-wr3c-6c22-m9v6/GHSA-wr3c-6c22-m9v6.json
CWE IDs: []
Alternative ID: N/A
Finding: F159
Auto approve: 1