First published: Mon Jul 10 2023(Updated: )
### Impact The product performs authorization checks incorrectly when an unauthorized actor tries to access a resource or perform an actions. The attacker can view and freely perform actions to add, modify, or delete rules. ### Patches Update to version 3.4.1 or apply this patch manually https://github.com/pimcore/customer-data-framework/commit/f15668c86db254e86ba7ac895bc3cdd1a2a3cc45.patch ### Workarounds Apply https://github.com/pimcore/customer-data-framework/commit/f15668c86db254e86ba7ac895bc3cdd1a2a3cc45.patch manually. ### References https://huntr.dev/bounties/1dcb4f01-e668-4aa3-a6a3-838532e500c6/
Credit: security@huntr.dev security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Pimcore Customer Management Framework | <3.4.1 |
https://github.com/pimcore/customer-data-framework/commit/f15668c86db254e86ba7ac895bc3cdd1a2a3cc45
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The product performs authorization checks incorrectly when an unauthorized actor tries to access a resource or perform an actions, allowing the attacker to view and freely perform actions to add, modify, or delete rules.
You can update to version 3.4.1 or manually apply the patch provided at the given URL: [Patch URL](https://github.com/pimcore/customer-data-framework/commit/f15668c86db254e86ba7ac895bc3cdd1a2a3cc45).
The severity of CVE-2023-3574 is medium with a CVSS score of 6.5.
CVE-2023-3574 falls under CWE categories 285 and 863.