Skip to content

eZ Platform users with the Company admin role can assign any role to any user

Critical severity GitHub Reviewed Published Nov 10, 2022 in ezsystems/ezpublish-kernel • Updated Jan 7, 2023

Package

composer ezsystems/ezpublish-kernel (Composer)

Affected versions

>= 7.5.0, < 7.5.30

Patched versions

7.5.30

Description

Critical severity. Users with the Company admin role (introduced by the company account feature in v4) can assign any role to any user. This also applies to any other user that has the role / assign policy. Any subtree limitation in place does not have any effect.

The role / assign policy is typically only given to administrators, which limits the scope in most cases, but please verify who has this policy in your installaton. The fix ensures that subtree limitations are working as intended.

References

@glye glye published to ezsystems/ezpublish-kernel Nov 10, 2022
Published to the GitHub Advisory Database Nov 10, 2022
Reviewed Nov 10, 2022
Last updated Jan 7, 2023

Severity

Critical

Weaknesses

No CWEs

CVE ID

No known CVE

GHSA ID

GHSA-99r3-xmmq-7q7g
Checking history
See something to contribute? Suggest improvements for this vulnerability.