VDB
Sign up
MEDIUM5.5

GHSA-m59h-42jf-cphr

Sprig Plugin for Craft CMS potentially discloses sensitive information via Sprig Playground

Quick fix

GHSA-m59h-42jf-cphr — putyourlightson/craft-sprig: upgrade to the fixed version with the command below.

composer require putyourlightson/craft-sprig:^2.15.2

Details

Admin users, and users with explicit permission to access the Sprig Playground, could potentially expose the security key, credentials, and other sensitive configuration data, in addition to running the `hashData()` signing function.

This issue was mitigated in versions 3.7.2 and 2.15.2 by disabling access to the Sprig Playground entirely when `devMode` is disabled, by default. It is possible to override this behaviour using a new `enablePlaygroundWhenDevModeDisabled` that defaults to `false`.

References:

- https://github.com/putyourlightson/craft-sprig/commit/db18c46f6dc5603828aa321a3a615adbd677d475 - https://github.com/putyourlightson/craft-sprig/commit/09c9da2ffb45a8857829f3390ae2578e26cfe03b

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/putyourlightson/craft-sprig
Introduced in: 2.0.0Fixed in: 2.15.2
Fixcomposer require putyourlightson/craft-sprig:^2.15.2
Packagist/putyourlightson/craft-sprig
Introduced in: 3.0.0Fixed in: 3.7.2
Fixcomposer require putyourlightson/craft-sprig:^3.7.2

References