-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stemmed from missing admin privilege checks in administrative endpoints. The commit adds critical authorization checks (isAccessAdmin() and checkAdminAccessOnly()) to servlets handling portlet deployment, file uploads, and import/export operations. The JobDomainPeasSessionController modifications show previous lack of domain access validation. These functions directly correspond to the described attack vector where low-privileged users could trigger maintenance mode via unprotected endpoints.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.silverpeas.core:silverpeas-core-war | maven | < 6.3.2 | 6.3.2 |
| org.silverpeas.core:silverpeas-core-web | maven | < 6.3.2 | 6.3.2 |
Ongoing coverage of React2Shell