github.com
https://github.com/advisories/GHSA-ghg6-32f9-2jp7 GHSA-HQ76-662X-7MW4
Pimcore includes vulnerable PHPOffice/PhpSpreadsheet
Description
### Summary Pimcore 10.6.x and Enterprise 10.6.x versions currently depend on PHPOffice/PhpSpreadsheet version 1.x, which has recently been identified with a security vulnerability (CVE-2024-45048). To mitigate this issue, it is recommended to update to the latest version 2.2.2. For more details, please refer to the official advisory: [GHSA-ghg6-32f9-2jp7](https://github.com/advisories/GHSA-ghg6-32f9-2jp7).
Description source: GitHub Advisory
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
pimcore/admin-ui-classic-bundleBrowse Packagist / pimcore/admin-ui-classic-bundle | GitHub Advisory | Before 1.3.11 · Fixed in 1.3.11 | affected |
| 1.4.0 to < 1.4.7 · Fixed in 1.4.7 | affected | ||
| 1.5.0 to < 1.5.4 · Fixed in 1.5.4 | affected | ||
pimcore/data-importerBrowse Packagist / pimcore/data-importer | GitHub Advisory | Before 1.8.9 · Fixed in 1.8.9 | affected |
| 1.9.0 to < 1.9.3 · Fixed in 1.9.3 | affected | ||
pimcore/pimcoreBrowse Packagist / pimcore/pimcore | GitHub Advisory | 10.6.9.0 to < 10.6.9.12 · Fixed in 10.6.9.12 | affected |
| 11.1.0.0 to < 11.1.6.11 · Fixed in 11.1.6.11 | affected |
References
3github.com
https://github.com/pimcore/pimcore github.com
https://github.com/pimcore/pimcore/security/advisories/GHSA-hq76-662x-7mw4