Abstrium Pydio Cells User Creation resource injection
Published May 30, 2023
8.8
HIGHCVSS 3.1
EPSS 1.13%
Description
A vulnerability classified as critical was found in Abstrium Pydio Cells 4.2.0. This vulnerability affects unknown code of the component User Creation Handler. The manipulation leads to improper control of resource identifiers. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.2.1 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-230212.
Affected products
-
- Version 4.2.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Abstrium | Pydio Cells | n/a |
|
- 4.2.0
No data.
No Red Hat product state for this CVE.
github.com/pydio/cells/v4
Go
Introduced 0 Fixed 4.2.1github.com/pydio/cells
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/pydio/cells/v4 | 0 | 4.2.1 |
| Go | github.com/pydio/cells | 0 | not fixed |
Remediation
No remediation recorded yet.
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-1562 Advisory
- https://github.com/advisories/GHSA-j327-c69h-4gh8 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-2980
- https://popalltheshells.medium.com/multiple-cves-affecting-pydio-cells-4-2-0-321e7e4712be exploitThird Party Advisory
- https://pydio.com/en/community/releases/pydio-cells/pydio-cells-enterprise-421 patchRelease Notes
- https://vuldb.com/?ctiid.230212 signaturepermissions-requiredPermissions RequiredThird Party AdvisoryVDB Entry
- https://vuldb.com/?id.230212 vdb-entrytechnical-descriptionPermissions RequiredThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-1562 | Advisory | |
| https://github.com/advisories/GHSA-j327-c69h-4gh8 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-2980 | ||
| https://popalltheshells.medium.com/multiple-cves-affecting-pydio-cells-4-2-0-321e7e4712be | exploitThird Party Advisory | |
| https://pydio.com/en/community/releases/pydio-cells/pydio-cells-enterprise-421 | patchRelease Notes | |
| https://vuldb.com/?ctiid.230212 | signaturepermissions-requiredPermissions RequiredThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?id.230212 | vdb-entrytechnical-descriptionPermissions RequiredThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.