4.3

CVE-2022-29858

Exploit
Silverstripe silverstripe/assets through 1.10 is vulnerable to improper access control that allows protected images to be published by changing an existing image short code on website content.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SilverstripeAssets Version < 1.10.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.96% 0.569
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

https://www.silverstripe.org/download/security-releases/
Vendor Advisory
Not Applicable
https://forum.silverstripe.org/c/releases
Vendor Advisory
Release Notes
https://www.silverstripe.org/blog/tag/release
Vendor Advisory
Release Notes
https://github.com/silverstripe/silverstripe-assets/commit/5f6a73b010c01587ffbfb954441f6b7cbb54e767
Patch
Third Party Advisory
https://huntr.dev/bounties/90e17d95-9f2f-44eb-9f26-49fa13a41d5a/
Third Party Advisory
Exploit
https://www.silverstripe.org/download/security-releases/cve-2022-29858
Vendor Advisory
Release Notes