lowVulnerability
GHSA-9m6v-8fxc-4r44
### Impact The users endpoint controller exposes a project's apiKey field to the logged-in user, provided they have permission for that endpoint. This only has impact if a project itself uses that specific field, Sulu itself does nothing with it and has no authentication per apiKey in its core. ### Patches A patch is released with Version 2.6.23 and 3.0.5. ### Workarounds Remove the field descriptor by patch the UserController.php File in Sulu Security Bundle.
Properties
- ghsa_id
- GHSA-9m6v-8fxc-4r44
- summary
- Sulu: Used API Keys may be available via Admin API
- severity
- low
- cve_id
- GHSA-9m6v-8fxc-4r44
- is_ghsa_only
- true
- ghsa_published
- 2026-05-18T17:34:06Z
- source_url
- https://github.com/advisories/GHSA-9m6v-8fxc-4r44
- ghsa_updated
- 2026-05-18T17:34:07Z
Related Entities (4)
AFFECTS (1)
→[Software]composer/sulu/sulu
HAS_WEAKNESS (1)
→[Weakness]Improper Access Control
REPORTED_BY (1)
→[Source]GitHub Advisory Database
VULNERABLE_TO (1)
←[Software]composer/sulu/sulu
Explore deeper with Ninja Signal's threat intelligence graph