The GridField print view incorrectly validates the permission of DataObjects potentially allowing a content author to view records they are not authorised to access.
Upgrade to silverstripe/framework
4.12.5 or above to address the issue.
Reported by Stephan Bauer from relaxt Webdienstleistungsagentur GmbH
{ "nvd_published_at": "2023-04-26T14:15:09Z", "cwe_ids": [ "CWE-862" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-04-26T19:47:07Z" }