GHSA-2237-5r9w-vm8j

Suggest an improvement
Source
https://github.com/advisories/GHSA-2237-5r9w-vm8j
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-2237-5r9w-vm8j/GHSA-2237-5r9w-vm8j.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-2237-5r9w-vm8j
Published
2025-02-07T20:50:20Z
Modified
2025-02-07T21:01:08Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Connect-CMS information that is restricted to viewing is visible
Details

Impact

  • Information that is restricted from viewing in the search results of site searches (※) can still be viewed via the main text (a feature added in v1.8.0).
    • Impact by version
      • v1.8.0 ~ v1.8.3: It will be displayed in the text.
      • v1.8.0 and earlier: It will not be displayed in the body of the text, but the title (frame name) will be displayed with a link.
    • Target viewing restriction function
      • Frame publishing function (private, limited publishing)
      • IP Restriction Page
      • Password setting page

Patches (fixed version)

  • Apply v1.8.4.

Workarounds

  • Remove the site search (e.g. hide frames).。

References

none

Database specific
{
    "cwe_ids":  [
        "CWE-200"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-02-07T20:50:20Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

Packagist / opensource-workshop/connect-cms

Package

Name
opensource-workshop/connect-cms
Purl
pkg:composer/opensource-workshop/connect-cms

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.8.4

Affected versions

v0.*
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.*
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.3.0
v1.3.1
v1.3.2
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3

Database specific

last_known_affected_version_range
"<= 1.8.3"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-2237-5r9w-vm8j/GHSA-2237-5r9w-vm8j.json"