Miggo Logo

GHSA-9cw3-j7wg-jwj8: Neos Flow Information disclosure in entity security

4.3

CVSS Score
3.1

Basic Information

CVE ID
-
EPSS Score
-
CWE
-
Published
5/17/2024
Updated
5/17/2024
KEV Status
No
Technology
TechnologyPHP

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
neos/flowcomposer>= 3.0.0, < 3.0.123.0.12
neos/flowcomposer>= 3.1.0, < 3.1.103.1.10
neos/flowcomposer>= 3.2.0, < 3.2.133.2.13
neos/flowcomposer>= 3.3.0, < 3.3.133.3.13
neos/flowcomposer>= 4.0.0, < 4.0.64.0.6

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

I* you *** us** *ntity s**urity *n* w*nt** to s**ur* *ntiti*s not just **s** on t** us*r's rol*, *ut on som* prop*rty o* t** us*r (lik* t** *omp*ny ** **lon*s to), *ntity s**urity *i* not work prop*rly to**t**r wit* t** *o*trin* qu*ry *****. T*is *ou

Reasoning

No *n*lysis *v*il**l*