Blog | G5 Cyber Security

Undocumented authentication bypass issue in AEM Package Manager [Blog updated]

Adobe Experience Manager (AEM) is a content management solution for building digital customer experiences. Security researchers and Detectify Crowdsource members Ai Ho (@j3ssiejjj) and Bao Bui (@Jok3rDb), discovered the issue. The vulnerability occurs when default security controls are manually turned off on the Package Manager content tree, by default /etc/packages. This issue allows an unauthorized user to view and download packages. The vulnerability does not require a CVE from Adobe because AEM has the necessary security controls enabled by default to help protect customers.”]

Source: https://labs.detectify.com/2021/06/28/aem-crx-bypass-0day-control-over-some-enterprise-aem-crx-package-manager/

Exit mobile version