CVE-2022-48367
Description
An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Access control based on object state in eZ Publish Ibexa Kernel before 7.5.28 is mishandled, allowing unauthorized content access.
Vulnerability
Description
An issue in eZ Publish Ibexa Kernel (and related packages) before version 7.5.28 causes object state limitations to be ineffective [1][4]. Object state limitations are a policy mechanism used in roles to restrict access to content based on specific state values. Due to a flawed earlier update, these limitations became inoperative, granting access regardless of the object state [4].
Exploitation
No authentication is required to exploit this flaw; an attacker who knows the URL of otherwise restricted content can access it directly [4]. The vulnerability affects multiple branches, including Ibexa DXP versions 4.1.*, 4.0.*, and eZ Platform kernel versions 1.3.* and 7.5.* [4].
Impact
Successful exploitation bypasses intended access control, potentially exposing sensitive content that should have been hidden based on object state values. The severity is rated High [4]. Depending on frontend configuration, simply knowing the content URL may be sufficient to gain unauthorized access [4].
Mitigation
The issue is fixed in eZ Publish Kernel version 7.5.28, as well as in Ibexa DXP v4.1.2, v4.0.5, v3.3.18, and eZ Platform v2.5.29 [4]. Administrators using object state limitations should apply the relevant update immediately [4].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ezsystems/ezpublish-kernelPackagist | >= 7.5.0, < 7.5.28 | 7.5.28 |
Affected products
3- eZ Publish/Ibexa Kerneldescription
- Range: <7.5.28
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-h5v2-wrhp-5v35ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-48367ghsaADVISORY
- developers.ibexa.co/security-advisories/ibexa-sa-2022-004-ineffective-object-state-limitation-and-unauthenticated-fastly-purgeghsaWEB
- github.com/ezsystems/ezpublish-kernel/security/advisories/GHSA-5x4f-7xgq-r42xghsaWEB
News mentions
0No linked articles in our index yet.