CVE-2024-29197

CVSS V2 None CVSS V3 None
Description
Pimcore is an Open Source Data & Experience Management Platform. Any call with the query argument `?pimcore_preview=true` allows to view unpublished sites. In previous versions of Pimcore, session information would propagate to previews, so only a logged in user could open a preview. This no longer applies. Previews are broad open to any user and with just the hint of a restricted link one could gain access to possible confident / unreleased information. This vulnerability is fixed in 11.2.2 and 11.1.6.1.
Overview
  • CVE ID
  • CVE-2024-29197
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-03-26T15:10:41.792Z
  • Last Modified Date
  • 2024-03-26T15:10:41.792Z
History
Created Old Value New Value Data Type Notes
2024-06-26 02:50:15 Added to TrackCVE