CVE-2020-6165Incorrect Default Permissions in Silverstripe

Severity
5.3MEDIUMNVD
EPSS
0.2%
top 63.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 15
Latest updateMay 24

Description

SilverStripe 4.5.0 allows attackers to read certain records that should not have been placed into a result set. This affects silverstripe/recipe-cms. The automatic permission-checking mechanism in the silverstripe/graphql module does not provide complete protection against lists that are limited (e.g., through pagination), resulting in records that should have failed a permission check being added to the final result set. GraphQL endpoints are configured by default (e.g., for assets), but the ad

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

Packagistsilverstripe/graphql3.2.03.2.4
Packagistsilverstripe/recipe-cms4.5.04.5.3
NVDsilverstripe/silverstripe3.2.03.2.4+2

🔴Vulnerability Details

2
GHSA
Silverstripe has Incorrect Default Permissions2022-05-24
OSV
Silverstripe has Incorrect Default Permissions2022-05-24