Skip to content

Commit a461c10

Browse files
authored
Merge pull request #592 from creative-commoners/pulls/master/silverstripe-490-release-cves
Add CVE-2021-36150 and CVE-2021-28661 which were disclosed with the Silverstripe 4.9.0 release
2 parents b442a2f + 845246b commit a461c10

File tree

2 files changed

+16
-0
lines changed

2 files changed

+16
-0
lines changed
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
title: "CVE-2021-36150 - Insert from files link text - Reflective (self) Cross Site Scripting"
2+
link: https://www.silverstripe.org/download/security-releases/CVE-2021-36150
3+
cve: CVE-2021-36150
4+
branches:
5+
1.0.x:
6+
time: 2021-10-05 05:18:20
7+
versions: ['>=1.0.0', '<1.8.1']
8+
reference: composer://silverstripe/admin
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
title: "CVE-2021-28661 Default GraphQL permission checker not inherited by query subclass"
2+
link: https://www.silverstripe.org/download/security-releases/CVE-2021-28661
3+
cve: CVE-2021-28661
4+
branches:
5+
3.0.x:
6+
time: 2021-06-07 22:31:00
7+
versions: ['>=3.0.0', '<3.5.2']
8+
reference: composer://silverstripe/graphql

0 commit comments

Comments
 (0)