CVE-2022-41876
moderate-risk
Published 2022-11-10
ezplatform-graphql is a GraphQL server implementation for Ibexa DXP and Ibexa Open Source. Versions prior to 2.3.12 and 1.0.13 are subject to Insecure Storage of Sensitive Information. Unauthenticated GraphQL queries for user accounts can expose password hashes of users that have created or modified content, typically administrators and editors. This issue has been patched in versions 2.3.12, and 1.0.13 on the 1.X branch. Users unable to upgrade can remove the "passwordHash" entry from "src/bundle/Resources/config/graphql/User.types.yaml" in the GraphQL package, and other properties like hash type, email, login if you prefer.
Do I need to act?
~
6.8% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10
High
NETWORK
/ LOW complexity
Affected Products (2)
Ezplatform-Graphql
Ezplatform-Graphql
Affected Vendors
References (2)
Third Party Advisory
https://github.com/ezsystems/ezplatform-graphql/security/advisories/GHSA-c7pc-pg...
Third Party Advisory
https://github.com/ezsystems/ezplatform-graphql/security/advisories/GHSA-c7pc-pg...
42
/ 100
moderate-risk
Severity
26/34 · High
Exploitability
9/34 · Low
Exposure
7/34 · Low