PT-2023-31900 · Pimcore · Pimcore
CVE-2023-5192
·
Publicado
2023-09-26
·
Atualizado
2023-09-29
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
pimcore/demo versions prior to 10.3.0
Description
The issue concerns excessive data query operations in a large data table. Additionally, introspection is enabled on the demo site
demo.pimcore.fun, which allows users to run introspection queries. This presents a potential schema information disclosure risk due to the exposure of schema details through GraphQL, a feature available for users on the demo site.Recommendations
For versions prior to 10.3.0, update to version 10.3.0 or later to resolve the issue.
As a temporary workaround, consider disabling the GraphQL feature on the demo site to minimize the risk of schema information disclosure.
Restrict access to introspection queries on
demo.pimcore.fun to prevent potential misuse.Exploit
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Pimcore