PT-2020-10457 · Pydio+1 · Pydio Enterprise+2

Published

2020-03-17

·

Updated

2020-08-24

·

CVE-2019-20452

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pydio Core versions prior to 8.2.4 Pydio Enterprise versions prior to 8.2.4
Description A PHP object injection issue is present in the page plugins/core.access/src/RecycleBinManager.php, allowing an authenticated user with basic privileges to inject objects and achieve remote code execution.
Recommendations For Pydio Core versions prior to 8.2.4, update to version 8.2.4 or later to resolve the issue. For Pydio Enterprise versions prior to 8.2.4, update to version 8.2.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the RecycleBinManager.php page until a patch is available.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20452

Affected Products

Php
Pydio Core
Pydio Enterprise