[MAVEN:GHSA-VPP3-HPCM-V944] Broken access control in Silverpeas

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

The "Create a Space" feature in Silverpeas Core 6.3.1 is reserved for use by administrators. This function suffers from broken access control, allowing any authenticated user to create a space by navigating to the correct URL.

Package Affected Version
pkg:maven/org.silverpeas.core/silverpeas-core-web < 6.3.2
ID
MAVEN:GHSA-VPP3-HPCM-V944
Severity
moderate
URL
https://github.com/advisories/GHSA-vpp3-hpcm-v944
Published
2023-12-13T15:30:58
(9 months ago)
Modified
2023-12-18T21:39:31
(9 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.silverpeas.core/silverpeas-core-web org.silverpeas.core silverpeas-core-web < 6.3.2
Fixed pkg:maven/org.silverpeas.core/silverpeas-core-web org.silverpeas.core silverpeas-core-web = 6.3.2
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...