MEDIUM5.4
GHSA-j5g9-j7r4-6qvx
Craft CMS Privilege Escalation
Quick fix
GHSA-j5g9-j7r4-6qvx — craftcms/cms: upgrade to the fixed version with the command below.
composer require craftcms/cms:^4.5.11Details
### Impact
This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft with certain user permissions setups.
### Patches
This has been fixed in Craft 4.4.16 and Craft 3.9.6. Users should ensure they are running at least those versions.
### References
https://github.com/craftcms/cms/pull/13932 https://github.com/craftcms/cms/pull/13931 https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4511---2023-11-16 https://github.com/craftcms/cms/blob/v3/CHANGELOG.md#396---2023-11-16
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/craftcms/cms
Introduced in:
4.0.0-RC1Fixed in: 4.5.11Fix
composer require craftcms/cms:^4.5.11References
- https://github.com/craftcms/cms/security/advisories/GHSA-j5g9-j7r4-6qvx[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-21622[ADVISORY]
- https://github.com/craftcms/cms/pull/13931[WEB]
- https://github.com/craftcms/cms/pull/13932[WEB]
- https://github.com/craftcms/cms/commit/76caf9af07d9964be0fd362772223be6a5f5b6aa[WEB]
- https://github.com/craftcms/cms/commit/be81eb653d633833f2ab22510794abb6bb9c0843[WEB]
- https://github.com/craftcms/cms[PACKAGE]
- https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4511---2023-11-16[WEB]
- https://github.com/craftcms/cms/blob/v3/CHANGELOG.md#396---2023-11-16[WEB]