eZ publish 3.4.4 through 3.7 before 20050722 applies certain permissions on the node level, which allows remote authenticated users to bypass the original permissions on embedded objects in XML fields and read these objects.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ez_publish | Ez | 3.4.4 (including) | 3.7 (including) |
Ezpublish | Ubuntu | dapper | * |
Ezpublish | Ubuntu | edgy | * |
Ezpublish | Ubuntu | feisty | * |
Ezpublish | Ubuntu | gutsy | * |