MEDIUM6.1
GHSA-rfvw-5848-gxc5
Silverstripe Flash Clipboard Reflected XSS
Quick fix
GHSA-rfvw-5848-gxc5 — silverstripe/framework: upgrade to the fixed version with the command below.
composer require silverstripe/framework:^4.3.5Details
SilverStripe versions 3.0.0 until 4.3.5 and 4.4.4 are vulnerable to Flash Clipboard Reflected XSS. Versions 4.3.5 and 4.4.4 of `silverstripe/framework` and version 1.3.5 of `silverstripe/admin` contain a fix for this issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/silverstripe/framework
Introduced in:
3.0.0Fixed in: 4.3.5Fix
composer require silverstripe/framework:^4.3.5Packagist/silverstripe/admin
Introduced in:
0Fixed in: 1.3.5Fix
composer require silverstripe/admin:^1.3.5Packagist/silverstripe/framework
Introduced in:
4.4.0-rc1Fixed in: 4.4.4Fix
composer require silverstripe/framework:^4.4.4References
- https://nvd.nist.gov/vuln/detail/CVE-2019-12205[ADVISORY]
- https://github.com/silverstripe/silverstripe-admin/commit/6e6fa5c618b9dbf4cc0a56704834bfa1d5b0d18e[WEB]
- https://forum.silverstripe.org/c/releases[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/CVE-2019-12205.yaml[WEB]
- https://www.silverstripe.org/download/security-releases[WEB]
- https://www.silverstripe.org/download/security-releases/CVE-2019-12205[WEB]
- https://www.silverstripe.org/download/security-releases/cve-2019-12205[WEB]