{"id":"GHSA-32rx-xvvr-4xv9","summary":"easyadmin-extension-bundle action case insensitivity","details":"In alterphp/easyadmin-extension-bundle, role based access rules do not handle action name case sensitivity which may lead to unauthorized access.","modified":"2024-11-29T05:32:41.671258Z","published":"2024-05-15T17:45:51Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-05-15T17:45:51Z","nvd_published_at":null,"cwe_ids":[],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/alterphp/EasyAdminExtensionBundle/commit/68407ca5be644d1c53fb894453df951230afc6dc"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/alterphp/easyadmin-extension-bundle/2018-10-02.yaml"},{"type":"WEB","url":"https://github.com/alterphp/EasyAdminExtensionBundle/releases/tag/v1.3.1"}],"affected":[{"package":{"name":"alterphp/easyadmin-extension-bundle","ecosystem":"Packagist","purl":"pkg:composer/alterphp/easyadmin-extension-bundle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.3.0"},{"fixed":"1.3.1"}]}],"versions":["v1.3.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-32rx-xvvr-4xv9/GHSA-32rx-xvvr-4xv9.json"}},{"package":{"name":"alterphp/easyadmin-extension-bundle","ecosystem":"Packagist","purl":"pkg:composer/alterphp/easyadmin-extension-bundle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.2.0"},{"fixed":"1.2.11"}]}],"versions":["1.2.6","v1.2.1","v1.2.10","v1.2.2","v1.2.3","v1.2.4","v1.2.5","v1.2.7","v1.2.8","v1.2.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-32rx-xvvr-4xv9/GHSA-32rx-xvvr-4xv9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"}]}