GHSA-qm2j-qvq3-j29v
Record titles for restricted records can be viewed if exposed by GridFieldAddExistingAutocompleter
Quick fix
GHSA-qm2j-qvq3-j29v — silverstripe/framework: upgrade to the fixed version with the command below.
composer require silverstripe/framework:^4.13.39Details
### Impact If a user should not be able to see a record, but that record can be added to a `GridField` using the `GridFieldAddExistingAutocompleter` component, the record's title can be accessed by that user.
**Base CVSS:** [4.3](https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:F/RL:O/RC:C&version=3.1) **Reported by:** Nick K - LittleMonkey, [littlemonkey.co.nz](http://littlemonkey.co.nz/)
### References - https://www.silverstripe.org/download/security-releases/CVE-2023-48714
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 4.13.39composer require silverstripe/framework:^4.13.395.0.0Fixed in: 5.1.11composer require silverstripe/framework:^5.1.11References
- https://github.com/silverstripe/silverstripe-framework/security/advisories/GHSA-qm2j-qvq3-j29v[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-48714[ADVISORY]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/CVE-2023-48714.yaml[WEB]
- https://github.com/silverstripe/silverstripe-framework[PACKAGE]
- https://www.silverstripe.org/download/security-releases/CVE-2023-48714[WEB]