lowVulnerability

GHSA-9m6v-8fxc-4r44

### Impact The users endpoint controller exposes a project's apiKey field to the logged-in user, provided they have permission for that endpoint. This only has impact if a project itself uses that specific field, Sulu itself does nothing with it and has no authentication per apiKey in its core. ### Patches A patch is released with Version 2.6.23 and 3.0.5. ### Workarounds Remove the field descriptor by patch the UserController.php File in Sulu Security Bundle.

Properties

ghsa_id
GHSA-9m6v-8fxc-4r44
summary
Sulu: Used API Keys may be available via Admin API
severity
low
cve_id
GHSA-9m6v-8fxc-4r44
is_ghsa_only
true
ghsa_published
2026-05-18T17:34:06Z
source_url
https://github.com/advisories/GHSA-9m6v-8fxc-4r44
ghsa_updated
2026-05-18T17:34:07Z

Related Entities (4)

AFFECTS (1)

[Software]composer/sulu/sulu

HAS_WEAKNESS (1)

[Weakness]Improper Access Control

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]composer/sulu/sulu

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-9m6v-8fxc-4r44 — Ninja Signal Threat Intelligence | Ninja Signal