CVE & CISA-KEV Catalog

CVE-2023-25575

HIGH
7.7
CVSS v3
NVD

Description

API Platform Core is the server component of API Platform: hypermedia and GraphQL APIs. Resource properties secured with the `security` option of the `ApiPlatform\Metadata\ApiProperty` attribute can be disclosed to unauthorized users. The problem affects most serialization formats, including raw JSON, which is enabled by default when installing API Platform. Custom serialization formats may also be impacted. Only collection endpoints are affected by the issue, item endpoints are not. The JSON-LD format is not affected by the issue. The result of the security rule is only executed for the first item of the collection. The result of the rule is then cached and reused for the next items. This bug can leak data to unauthorized users when the rule depends on the value of a property of the item. This bug can also hide properties that should be displayed to authorized users. This issue impacts the 2.7, 3.0 and 3.1 branches. Please upgrade to versions 2.7.10, 3.0.12 or 3.1.3. As a workaround, replace the `cache_key` of the context array of the Serializer inside a custom normalizer that works on objects if the security option of the `ApiPlatform\Metadata\ApiProperty` attribute is used.

How to fix

Remediation Available
coreNVD
Affected:>= 3.1.0, < 3.1.3Fixed in:3.1.3CVE-2023-25575derived from NVD

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeChanged

Impact

ConfidentialityHigh
IntegrityNone
AvailabilityNone

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Exploit Intelligence

0.60%probability of exploitation in 30 days
44thpercentile

Moderate risk: more likely to be exploited than 44% of all known CVEs.

References

Vendor Advisory1
Embed a live status badge for CVE-2023-25575
CVE-2023-25575 severity badge

Markdown

[![CVE-2023-25575](https://tridentstack.com/cve/badge/CVE-2023-25575.svg)](https://tridentstack.com/cve/CVE-2023-25575)

HTML

<a href="https://tridentstack.com/cve/CVE-2023-25575"><img src="https://tridentstack.com/cve/badge/CVE-2023-25575.svg" alt="CVE-2023-25575"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

Start free

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2024-11-21.