VDB
Sign up
HIGH7.5

GHSA-62ch-j6x7-722j

Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature

Quick fix

GHSA-62ch-j6x7-722j — opensource-workshop/connect-cms: upgrade to the fixed version with the command below.

composer require opensource-workshop/connect-cms:^1.41.1

Details

# Security Advisory — Page Content Retrieval (Improper Authorization)

## Summary

An improper authorization issue in the page content retrieval feature may allow retrieval of non-public information.

## Affected Versions

- 1.x series: <= 1.41.0 - 2.x series: <= 2.41.0

## Patched Versions

- 1.41.1 - 2.41.1

## Description

In part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version.

## Solution

Update to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later.

## Credits

OpenSource WorkShop thanks **Sho Odagiri** (小田切 祥) of **GMO Cybersecurity by Ierae, Inc.** for reporting this vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/opensource-workshop/connect-cms
Introduced in: 0Fixed in: 1.41.1
Fixcomposer require opensource-workshop/connect-cms:^1.41.1
Packagist/opensource-workshop/connect-cms
Introduced in: 2.0.0Fixed in: 2.41.1
Fixcomposer require opensource-workshop/connect-cms:^2.41.1

References