CVE-2022-48365

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
12/03/2023
Last modified:
04/03/2025

Description

An issue was discovered in eZ Platform Ibexa Kernel before 1.3.26. The Company admin role gives excessive privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibexa:digital_experience_platform:*:*:*:*:*:*:*:* 3.3.0 (including) 3.3.28 (excluding)
cpe:2.3:a:ibexa:digital_experience_platform:*:*:*:*:*:*:*:* 4.2.0 (including) 4.2.3 (excluding)
cpe:2.3:a:ibexa:ez_platform:*:*:*:*:*:*:*:* 2.5.0 (including) 2.5.31 (excluding)
cpe:2.3:o:ibexa:ez_platform_kernel:*:*:*:*:*:*:*:* 1.3.0 (including) 1.3.26 (excluding)
cpe:2.3:o:ibexa:ez_platform_kernel:*:*:*:*:*:*:*:* 7.5.0 (including) 7.5.30 (excluding)