MEDIUM4.3
GHSA-89q6-98xx-4ffw
Silverstripe Reports are still accessible even when `canView()` returns false
Quick fix
GHSA-89q6-98xx-4ffw — silverstripe/reports: upgrade to the fixed version with the command below.
composer require silverstripe/reports:^5.2.3Details
Reports can be accessed by their direct URL by any user who has access to view the reports admin section, even if the `canView()` method for that report returns `false`.
## References - https://www.silverstripe.org/download/security-releases/cve-2024-29885
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/silverstripe/reports
Introduced in:
0Fixed in: 5.2.3Fix
composer require silverstripe/reports:^5.2.3References
- https://github.com/silverstripe/silverstripe-reports/security/advisories/GHSA-89q6-98xx-4ffw[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-29885[ADVISORY]
- https://github.com/silverstripe/silverstripe-reports/commit/0351106c18ad4246d983b5f4e082c09c382121f4[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/reports/CVE-2024-29885.yaml[WEB]
- https://github.com/silverstripe/silverstripe-reports[PACKAGE]
- https://www.silverstripe.org/download/security-releases/cve-2024-29885[WEB]