CVE-2023-32062
published 2023-11-27CVE-2023-32062: OroPlatform is a package that assists system and user calendar management. Back-office users can access information from any system calendar event, bypassing…
PriorityP420medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.54%
42.1th percentile
OroPlatform is a package that assists system and user calendar management. Back-office users can access information from any system calendar event, bypassing ACL security restrictions due to insufficient security checks. This vulnerability has been patched in version 5.1.1.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oro | calendar-bundle | 4.2.0 – 4.2.6 | — |
| oro | calendar-bundle | >= 5.0.0 < 5.0.7 | 5.0.7 |
| oro | calendar-bundle | >= 5.1.0 < 5.1.1 | 5.1.1 |
| oroinc | crm | — | — |
| oroinc | crm | — | — |
| oroinc | crm | — | — |
| oroinc | oroplatform | 4.2.0 – 4.2.6 | — |
| oroinc | oroplatform | >= 5.0.0 < 5.0.7 | 5.0.7 |
| oroinc | oroplatform | >= 5.1.0 < 5.1.1 | 5.1.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OroCalendarBundle has incorrect system calendar events visibility
ghsa·2023-11-27
CVE-2023-32062 [MEDIUM] CWE-284 OroCalendarBundle has incorrect system calendar events visibility
OroCalendarBundle has incorrect system calendar events visibility
OroPlatform is a package that assist system and user calendar management. Back-office users can access information from any system calendar event, bypassing ACL security restrictions due to insufficient security checks.
OSV
OroCalendarBundle has incorrect system calendar events visibility
osv·2023-11-27
CVE-2023-32062 [MEDIUM] OroCalendarBundle has incorrect system calendar events visibility
OroCalendarBundle has incorrect system calendar events visibility
OroPlatform is a package that assist system and user calendar management. Back-office users can access information from any system calendar event, bypassing ACL security restrictions due to insufficient security checks.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/oroinc/OroCalendarBundle/commit/460a8ffb63b10c76f2fa26d53512164851c4909bhttps://github.com/oroinc/OroCalendarBundle/commit/5f4734aa02088191c1c1d90ac0909f48610fe531https://github.com/oroinc/crm/security/advisories/GHSA-x2xm-p6vq-482ghttps://github.com/oroinc/OroCalendarBundle/commit/460a8ffb63b10c76f2fa26d53512164851c4909bhttps://github.com/oroinc/OroCalendarBundle/commit/5f4734aa02088191c1c1d90ac0909f48610fe531https://github.com/oroinc/crm/security/advisories/GHSA-x2xm-p6vq-482g
2023-11-27
Published