Pimcore Preview Documents are not restricted to logged in users anymore
Package
Affected versions
> 11.0.0, < 11.1.6.1
>= 11.2.0, < 11.2.2
Patched versions
11.1.6.1
11.2.2
Description
Published by the National Vulnerability Database
Mar 26, 2024
Published to the GitHub Advisory Database
Mar 26, 2024
Reviewed
Mar 26, 2024
Last updated
Mar 27, 2024
Summary
Any call with the query argument
?pimcore_preview=true
allows to view unpublished sites. Event if in incognito window. Due to the behaviour of how previews should work, this also applies to internal documents, say an intranet which could be really severe.Details
In previous versions of Pimcore, session information would propagate to previews, so only a logged in user could open a preview. This no longer applies. Previews are broad open to any user and with just the hint of a restricted link one could gain access to possible confident / unreleased information.
PoC
Impact
Any intranet or other restricted sites which are able to show a preview are affected. This could possibly be huge.
References