CVE-2014-2921
high
CVSS v3
—
CVSS v2
7.5
VIR risk
7.5
Description
Pimcore Vulnerable to PHP Object Injection Attacks
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — http://www.pimcore.org/en/resources/blog/pimcore+2.2+released_b442
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Packagist | pimcore/pimcore | >=1.4.9,<2.2.0 | 2.2.0 |
References
- http://openwall.com/lists/oss-security/2014/04/21/1
- http://www.pimcore.org/en/resources/blog/pimcore+2.2+released_b442
- https://github.com/pedrib/PoC/blob/master/pimcore-2.1.0.txt
- https://nvd.nist.gov/vuln/detail/CVE-2014-2921
- https://github.com/pimcore/pimcore/commit/3cb2683e669b5644f180d362cfa9614c09bef280
- https://github.com/pedrib/PoC/blob/caa03645e256a8b50f1101c983d39586ebc467ee/advisories/pimcore-2.1.0.txt
- https://github.com/pimcore/pimcore
CWEs
CWE-94
Verify integrity in audit chain (admin only). AS-IS.