logo

GHSA-wr3c-6c22-m9v6 typo3/neos

Package

Manager: composer
Name: typo3/neos
Vulnerable Version: >=1.1.0 <1.1.3 || >=1.2.0 <1.2.3

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

EPSS: N/A pctlN/A

Details

Privilege Escalation in TYPO3 Neos It has been discovered that TYPO3 Neos is vulnerable to Privilege Escalation. Logged in editors could access, create and modify content nodes that exist in the workspace of other editors.

Metadata

Created: 2024-06-05T17:28:04Z
Modified: 2024-06-05T17:28:04Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-wr3c-6c22-m9v6/GHSA-wr3c-6c22-m9v6.json
CWE IDs: []
Alternative ID: N/A
Finding: F159
Auto approve: 1