
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-29197 affects Pimcore, an Open Source Data & Experience Management Platform. The vulnerability allows unauthorized access to unpublished sites through preview functionality. Any call with the query argument ?pimcore_preview=true can expose unpublished content, including potentially confidential or unreleased information. The issue was discovered and disclosed on March 26, 2024, and has been fixed in versions 11.2.2 and 11.1.6.1 (GitHub Advisory).
The vulnerability stems from a change in how preview session information is handled. In previous versions, session information would propagate to previews, restricting access to logged-in users only. This security measure no longer applies, allowing any user, even in incognito mode, to access preview content. The vulnerability has been assigned a CVSS v3.1 base score of 6.5 (Medium) with vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N, indicating network accessibility with low attack complexity and no privileges required (GitHub Advisory).
The vulnerability can expose confidential and unreleased information through preview links. It particularly affects internal documents and intranet sites, potentially leading to unauthorized access to sensitive content. Any restricted sites with preview functionality are vulnerable, making the potential impact significant for organizations using Pimcore for internal or confidential content management (GitHub Advisory).
The vulnerability is easily exploitable by sending a request with the ?pimcore_preview=true parameter to an affected site. No authentication is required, and the attack can be performed from any browser, including incognito mode. A proof of concept demonstrates that unpublished documents can be accessed by simply opening preview links in an incognito tab (GitHub Advisory).
The vulnerability has been patched in Pimcore versions 11.2.2 and 11.1.6.1. Organizations running affected versions should upgrade to these patched versions immediately. The fix includes proper access control checks and logging of unauthorized access attempts (Pimcore Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."