CVE Vulnerabilities

CVE-2022-41876

Insecure Storage of Sensitive Information

Published: Nov 10, 2022 | Modified: Nov 15, 2022
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

ezplatform-graphql is a GraphQL server implementation for Ibexa DXP and Ibexa Open Source. Versions prior to 2.3.12 and 1.0.13 are subject to Insecure Storage of Sensitive Information. Unauthenticated GraphQL queries for user accounts can expose password hashes of users that have created or modified content, typically administrators and editors. This issue has been patched in versions 2.3.12, and 1.0.13 on the 1.X branch. Users unable to upgrade can remove the passwordHash entry from src/bundle/Resources/config/graphql/User.types.yaml in the GraphQL package, and other properties like hash type, email, login if you prefer.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Ezplatform-graphql Ibexa 1.0.0 (including) 1.0.13 (excluding)
Ezplatform-graphql Ibexa 2.0.0 (including) 2.3.12 (excluding)
Ezplatform-graphql Ibexa 2.0.0-beta1 (including) 2.0.0-beta1 (including)

References