QID 996830
Date Published: 2024-01-24
QID 996830: PHP (Composer) Security Update for silverstripe/framework (GHSA-qm2j-qvq3-j29v)
If a user should not be able to see a record, but that record can be added to a GridField using the GridFieldAddExistingAutocompleter component, the record's title can be accessed by that user.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-qm2j-qvq3-j29v for updates and patch information.
Vendor References
- GHSA-qm2j-qvq3-j29v -
github.com/advisories/GHSA-qm2j-qvq3-j29v
CVEs related to QID 996830
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qm2j-qvq3-j29v | silverstripe/framework |
|