Information Exposure Affecting ezsystems/ezpublish-kernel package, versions >=5.3.0, <5.3.12.1 >=5.4.0, <5.4.13.1 >=6.0.0, <6.7.9.1 >=6.8.0, <6.13.5.1 >=7.0.0, <7.2.4.1 >=7.3.0, <7.3.2.1


0.0
medium

Snyk CVSS

    Attack Complexity Low

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-PHP-EZSYSTEMSEZPUBLISHKERNEL-72636
  • published 28 Nov 2018
  • disclosed 26 Nov 2018
  • credit Unknown

Introduced: 26 Nov 2018

CVE NOT AVAILABLE CWE-200 Open this link in a new tab

How to fix?

Upgrade ezsystems/ezpublish-kernel to versions 7.3.2.1, 7.2.4.1, 6.13.5.1 , 6.7.9.1 or higher.

Overview

ezsystems/ezpublish-kernel Provides the Content Repository, its APIs, and the application's Symfony framework integration.

Affected versions of this package are vulnerable to Information Exposure. The REST API may be made to disclose the names of all available site accesses.

References