Description

### Summary Pimcore 10.6.x and Enterprise 10.6.x versions currently depend on PHPOffice/PhpSpreadsheet version 1.x, which has recently been identified with a security vulnerability (CVE-2024-45048). To mitigate this issue, it is recommended to update to the latest version 2.2.2. For more details, please refer to the official advisory: [GHSA-ghg6-32f9-2jp7](https://github.com/advisories/GHSA-ghg6-32f9-2jp7).

Description source: GitHub Advisory

Affected products and versions

3
ProductSourceVersion rangeStatus
GitHub AdvisoryBefore 1.3.11 · Fixed in 1.3.11affected
1.4.0 to < 1.4.7 · Fixed in 1.4.7affected
1.5.0 to < 1.5.4 · Fixed in 1.5.4affected
GitHub AdvisoryBefore 1.8.9 · Fixed in 1.8.9affected
1.9.0 to < 1.9.3 · Fixed in 1.9.3affected
GitHub Advisory10.6.9.0 to < 10.6.9.12 · Fixed in 10.6.9.12affected
11.1.0.0 to < 11.1.6.11 · Fixed in 11.1.6.11affected

References

3