Skip to content

Commit

Permalink
Merge pull request #710 from creative-commoners/pulls/master/january-…
Browse files Browse the repository at this point in the history
…patches

Add CVE details for January Silverstripe CMS patches
  • Loading branch information
xabbuh committed Jan 25, 2024
2 parents fd6a8b7 + 8eb1e76 commit e14352c
Show file tree
Hide file tree
Showing 3 changed files with 36 additions and 0 deletions.
11 changes: 11 additions & 0 deletions silverstripe/admin/CVE-2023-49783.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
title: "CVE-2023-49783 No permission checks for editing or deleting records with CSV import form"
link: https://www.silverstripe.org/download/security-releases/CVE-2023-49783
cve: CVE-2023-49783
branches:
1.13.x:
time: 2024-01-23 03:15:01
versions: ['>=1.0.0', '<1.13.19']
2.1.x:
time: 2024-01-23 03:15:49
versions: ['>=2.0.0', '<2.1.8']
reference: composer://silverstripe/admin
14 changes: 14 additions & 0 deletions silverstripe/framework/CVE-2023-48714.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
title: "CVE-2023-48714 Record titles for restricted records can be viewed if exposed by GridFieldAddExistingAutocompleter"
link: https://www.silverstripe.org/download/security-releases/CVE-2023-48714
cve: CVE-2023-48714
branches:
3.x:
time: null
versions: ['>=3.0.0', '<4.0.0']
4.13.x:
time: 2024-01-22 22:46:28
versions: ['>=4.0.0', '<4.13.39']
5.1.x:
time: 2024-01-22 22:58:52
versions: ['>=5.0.0', '<5.1.11']
reference: composer://silverstripe/framework
11 changes: 11 additions & 0 deletions silverstripe/graphql/CVE-2023-44401.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
title: "CVE-2023-44401 View permissions are bypassed for paginated lists of ORM data in GraphQL queries"
link: https://www.silverstripe.org/download/security-releases/CVE-2023-44401
cve: CVE-2023-44401
branches:
4.3.x:
time: 2024-01-22 23:19:50
versions: ['>=4.0.0', '<4.3.7']
5.1.x:
time: 2024-01-22 23:26:08
versions: ['>=5.0.0', '<5.1.3']
reference: composer://silverstripe/graphql

0 comments on commit e14352c

Please sign in to comment.