MEDIUM4.3
GHSA-jm6p-wfjg-xm7x
bookstack is vulnerable to Improper Access Control
Quick fix
GHSA-jm6p-wfjg-xm7x — ssddanbrown/bookstack: upgrade to the fixed version with the command below.
composer require ssddanbrown/bookstack:^21.11.2Details
bookstack is vulnerable to Improper Access Control.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/ssddanbrown/bookstack
Introduced in:
0Fixed in: 21.11.2Fix
composer require ssddanbrown/bookstack:^21.11.2References
- https://nvd.nist.gov/vuln/detail/CVE-2021-4026[ADVISORY]
- https://github.com/bookstackapp/bookstack/commit/b4fa82e3298a15443ca40bff205b7a16a1031d92[WEB]
- https://github.com/BookStackApp/BookStack/releases/tag/v21.11.2[WEB]
- https://github.com/bookstackapp/bookstack[WEB]
- https://huntr.dev/bounties/c6dfa80d-43e6-4b49-95af-cc031bb66b1d[WEB]