PT-2024-40358 · Silverstripe · Silverstripe

Published

2024-05-28

·

Updated

2024-05-28

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SilverStripe versions 3.7 through 4.x
Description The issue potentially discloses database connection details when SilverStripe is run in dev mode using the mysqli database driver. To mitigate this, sensitive parts of the connection information have been blacklisted from being included in dev mode stack traces when database errors occur.
Recommendations For SilverStripe versions 3.7 through 4.x, consider running the application outside of dev mode to minimize the risk of connection detail disclosure. As a temporary workaround, ensure that the blacklisting of sensitive connection information is properly configured to prevent exposure in dev mode stack traces.

Fix

Generation of Error Message Containing Sensitive Information

Weakness Enumeration

Related Identifiers

GHSA-M2HH-2M46-X6J5

Affected Products

Silverstripe