ezsystems/ezpublish-kernel Security Advisories for v7.5.20 (8)
- 
                        [LOW] Download route allows filename change in eZpublish kernelPKSA-z67k-j82n-m783 GHSA-946c-f9w6-2c25 Affected version: >=7.5.0,<7.5.31 Reported by: 
 GitHub
- 
                        [CRITICAL] Access control issue in ezsystems/ezpublish-kernelPKSA-6sj4-k5qk-7xf1 CVE-2022-48367 GHSA-h5v2-wrhp-5v35 Affected version: >=7.5.0,<7.5.28 Reported by: 
 GitHub
- 
                        [LOW] Timing attack in eZ Platform IbexaPKSA-6zrh-817h-wc9b CVE-2022-48366 GHSA-66m4-gc8h-hpjx Affected version: >=7.5.0,<7.5.29 Reported by: 
 GitHub
- 
                        [HIGH] Company admin role gives excessive privileges in eZ Platform IbexaPKSA-vyh4-xcqv-nk64 CVE-2022-48365 GHSA-qq2j-9pf8-g58c Affected version: >=7.5.0,<7.5.30 Reported by: 
 GitHub
- 
                        [CRITICAL] eZ Platform users with the Company admin role can assign any role to any userPKSA-c699-v1ks-dw56 GHSA-99r3-xmmq-7q7g Affected version: >=7.5.0,<7.5.30 Reported by: 
 GitHub
- 
                        [CRITICAL] Login timing attack in ezsystems/ezpublish-kernelPKSA-ns35-p1q3-5g4c GHSA-xfqg-p48g-hh94 Affected version: >=7.5.0,<7.5.29 Reported by: 
 GitHub
- 
                        [CRITICAL] Object state limitation has no effectPKSA-f72h-m83w-y9bn GHSA-5x4f-7xgq-r42x Affected version: >=7.5.0,<7.5.28 Reported by: 
 GitHub
- 
                        [CRITICAL] Code injection in ezsystems/ezpublish-kernelPKSA-h5v6-1rtg-7xrf CVE-2022-25337 GHSA-xwv6-v7qx-f5jc Affected version: >=7.5.0,<7.5.26 Reported by: 
 GitHub