Pimcore includes vulnerable PHPOffice/PhpSpreadsheet
Package
Affected versions
< 1.3.11
>= 1.4.0, < 1.4.7
>= 1.5.0, < 1.5.4
Patched versions
1.3.11
1.4.7
1.5.4
Description
Published to the GitHub Advisory Database
Sep 3, 2024
Reviewed
Sep 3, 2024
Last updated
Sep 3, 2024
Summary
Pimcore 10.6.x and Enterprise 10.6.x versions currently depend on PHPOffice/PhpSpreadsheet version 1.x, which has recently been identified with a security vulnerability (CVE-2024-45048). To mitigate this issue, it is recommended to update to the latest version 2.2.2. For more details, please refer to the official advisory: GHSA-ghg6-32f9-2jp7.
References