PT-2024-19009 · Pimcore · Pimcore/Customer-Data-Framework

Wisconaut

·

Published

2024-01-10

·

Updated

2024-01-18

·

CVE-2024-21667

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions pimcore/customer-data-framework versions prior to 4.0.6
Description An authenticated and unauthorized user can access the GDPR data extraction feature and query over the information returned, leading to customer data exposure. Permissions are not enforced when reaching the "/admin/customermanagementframework/gdpr-data/search-data-objects" endpoint, allowing an authenticated user without the permissions to access the endpoint and query the data available there. An unauthorized user can access PII data from customers.
Recommendations For versions prior to 4.0.6, update to version 4.0.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/admin/customermanagementframework/gdpr-data/search-data-objects" endpoint until the update is applied. Additionally, review and enforce proper permissions for all users to prevent unauthorized access to customer data.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-21667
GHSA-G273-WPPX-82W4

Affected Products

Pimcore/Customer-Data-Framework