PT-2024-40358 · Silverstripe · Silverstripe
Published
2024-05-28
·
Updated
2024-05-28
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SilverStripe versions 3.7 through 4.x
Description
The issue potentially discloses database connection details when SilverStripe is run in dev mode using the mysqli database driver. To mitigate this, sensitive parts of the connection information have been blacklisted from being included in dev mode stack traces when database errors occur.
Recommendations
For SilverStripe versions 3.7 through 4.x, consider running the application outside of dev mode to minimize the risk of connection detail disclosure. As a temporary workaround, ensure that the blacklisting of sensitive connection information is properly configured to prevent exposure in dev mode stack traces.
Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Silverstripe