Описание
silverstripe/framework has potential SQL Injection vulnerability in PostgreSQL database connector
A potential SQL injection vulnerability was identified by using the silverstripe/postgresql database adapter. While unlikely to be exploitable, we have patched silverstripe/framework to ensure that table names are safely escaped before being passed to database adapters or user code.
Ссылки
- https://github.com/silverstripe/silverstripe-framework/commit/48bd335648188df9dae72be1e5f9c808f3fe1e77
- https://github.com/silverstripe/silverstripe-framework/commit/fecedc2d98eeaaff6424fb59dc70ef6bdc6dc92d
- https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/SS-2018-020-1.yaml
- https://www.silverstripe.org/download/security-releases/ss-2018-020
Пакеты
Наименование
silverstripe/framework
composer
Затронутые версииВерсия исправления
>= 4.0.0-rc1, < 4.0.6
4.0.6
Наименование
silverstripe/framework
composer
Затронутые версииВерсия исправления
>= 4.1.0-rc1, < 4.1.4
4.1.4
Наименование
silverstripe/framework
composer
Затронутые версииВерсия исправления
>= 4.2.0-rc1, < 4.2.3
4.2.3
8.8 High
CVSS3
Дефекты
CWE-89
8.8 High
CVSS3
Дефекты
CWE-89