VYPR
Critical severityNVD Advisory· Published Mar 12, 2023· Updated Mar 4, 2025

CVE-2022-48367

CVE-2022-48367

Description

An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Access control based on object state in eZ Publish Ibexa Kernel before 7.5.28 is mishandled, allowing unauthorized content access.

Vulnerability

Description

An issue in eZ Publish Ibexa Kernel (and related packages) before version 7.5.28 causes object state limitations to be ineffective [1][4]. Object state limitations are a policy mechanism used in roles to restrict access to content based on specific state values. Due to a flawed earlier update, these limitations became inoperative, granting access regardless of the object state [4].

Exploitation

No authentication is required to exploit this flaw; an attacker who knows the URL of otherwise restricted content can access it directly [4]. The vulnerability affects multiple branches, including Ibexa DXP versions 4.1.*, 4.0.*, and eZ Platform kernel versions 1.3.* and 7.5.* [4].

Impact

Successful exploitation bypasses intended access control, potentially exposing sensitive content that should have been hidden based on object state values. The severity is rated High [4]. Depending on frontend configuration, simply knowing the content URL may be sufficient to gain unauthorized access [4].

Mitigation

The issue is fixed in eZ Publish Kernel version 7.5.28, as well as in Ibexa DXP v4.1.2, v4.0.5, v3.3.18, and eZ Platform v2.5.29 [4]. Administrators using object state limitations should apply the relevant update immediately [4].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
ezsystems/ezpublish-kernelPackagist
>= 7.5.0, < 7.5.287.5.28

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.