← Back

CVE-2022-48367

nvd nist
Published: Mar 12, 2023Modified: Mar 4, 2025

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled.

Affected (11)

5 products
Digital Experience Platform
Ez Platform Kernel
Ezplatform Http Cache Fastly
Fastly
Kernel
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Ibexa
From 3.3.0 to 3.3.18
From 4.0.0 to 4.0.5
From 4.1.0 to 4.1.2
Ibexa
From 1.3.0 to 1.3.17
From 7.5.0 to 7.5.28
Ibexa
From 1.1.0 to 1.1.9
From 2.0.0 to 2.0.11
Ibexa
From 4.0.0 to 4.0.5
From 4.1.0 to 4.1.2
Ibexa
From 4.0.0 to 4.0.7
From 4.1.0 to 4.1.4

Timeline

No history available yet.