{"api_version":"v1","generated_at":"2026-10-06T15:45:00+00:00","product":{"cve_count":4,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-pimcore-customer-data-framework-705ec329cd88","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"customer-data-framework","next_cursor":null,"observations":[{"affected":"4.0; 4.1; 4.2","affected_versions_present":true,"cve_id":"CVE-2024-11956","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-11956","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-01-28T14:14:01.837Z","patch_url":"","primary_source":"","published":"2025-01-28T13:46:27.639Z"},{"affected":"< 4.0.6","affected_versions_present":true,"cve_id":"CVE-2024-21667","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-21667","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-06-17T21:09:16.182Z","patch_url":"https://github.com/pimcore/customer-data-framework/commit/6c34515be2ba39dceee7da07a1abf246309ccd77","primary_source":"","published":"2024-01-11T01:05:35.979Z"},{"affected":"< 4.0.6","affected_versions_present":true,"cve_id":"CVE-2024-21666","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-21666","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-06-03T14:25:35.995Z","patch_url":"https://github.com/pimcore/customer-data-framework/security/advisories/GHSA-c38c-c8mh-vq68","primary_source":"","published":"2024-01-11T00:45:44.520Z"},{"affected":"< 4.0.5","affected_versions_present":true,"cve_id":"CVE-2023-49076","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-49076","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-06-05T13:27:42.356Z","patch_url":"https://github.com/pimcore/customer-data-framework/security/advisories/GHSA-xx63-4jr8-9ghc","primary_source":"","published":"2023-11-30T05:42:12.668Z"},{"affected":"< 3.3.9","affected_versions_present":true,"cve_id":"CVE-2023-32075","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-32075","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-01-24T16:38:09.717Z","patch_url":"https://github.com/pimcore/customer-data-framework/security/advisories/GHSA-x99j-r8vv-gwwj","primary_source":"","published":"2023-05-11T16:39:37.634Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"Pimcore"}}
