Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gm5x-hpmw-xpxg

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Silverstripe CMS information disclosure

In SilverStripe through 4.5.0, a specific URL path configured by default through the silverstripe/framework module can be used to disclose the fact that a domain is hosting a Silverstripe application. There is no disclosure of the specific version. The functionality on this URL path is limited to execution in a CLI context, and is not known to present a vulnerability through web-based access. As a side-effect, this preconfigured path also blocks the creation of other resources on this path (e.g. a page).

Пакеты

Наименование

silverstripe/cms

composer
Затронутые версииВерсия исправления

<= 4.5.0

Отсутствует

Наименование

silverstripe/framework

composer
Затронутые версииВерсия исправления

>= 4.0.0, < 4.4.7

4.4.7

Наименование

silverstripe/framework

composer
Затронутые версииВерсия исправления

>= 4.5.0, < 4.5.4

4.5.4

EPSS

Процентиль: 72%
0.00703
Низкий

7.5 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
nvd
больше 5 лет назад

In SilverStripe through 4.5.0, a specific URL path configured by default through the silverstripe/framework module can be used to disclose the fact that a domain is hosting a Silverstripe application. There is no disclosure of the specific version. The functionality on this URL path is limited to execution in a CLI context, and is not known to present a vulnerability through web-based access. As a side-effect, this preconfigured path also blocks the creation of other resources on this path (e.g. a page).

EPSS

Процентиль: 72%
0.00703
Низкий

7.5 High

CVSS3

Дефекты

CWE-200