[MAVEN:GHSA-28WG-8GV4-MPJF] Broken access control in Silverpeas

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control via the "Porlet Deployer" which allows administrators to deploy .WAR portlets.

Package Affected Version
pkg:maven/org.silverpeas.core/silverpeas-core-web < 6.3.2
ID
MAVEN:GHSA-28WG-8GV4-MPJF
Severity
moderate
URL
https://github.com/advisories/GHSA-28wg-8gv4-mpjf
Published
2023-12-13T15:30:58
(9 months ago)
Modified
2023-12-15T22:10:12
(9 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.silverpeas.core/silverpeas-core-web org.silverpeas.core silverpeas-core-web < 6.3.2
Fixed pkg:maven/org.silverpeas.core/silverpeas-core-web org.silverpeas.core silverpeas-core-web = 6.3.2
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...