Vulnerability Description
Silverstripe silverstripe/assets through 1.10 is vulnerable to improper access control that allows protected images to be published by changing an existing image short code on website content.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Silverstripe | Assets | < 1.10.1 |
Related Weaknesses (CWE)
References
- https://forum.silverstripe.org/c/releasesRelease NotesVendor Advisory
- https://github.com/silverstripe/silverstripe-assets/commit/5f6a73b010c01587ffbfbPatchThird Party Advisory
- https://huntr.dev/bounties/90e17d95-9f2f-44eb-9f26-49fa13a41d5a/ExploitThird Party Advisory
- https://www.silverstripe.org/blog/tag/releaseRelease NotesVendor Advisory
- https://www.silverstripe.org/download/security-releases/Not ApplicableVendor Advisory
- https://www.silverstripe.org/download/security-releases/cve-2022-29858Release NotesVendor Advisory
- https://forum.silverstripe.org/c/releasesRelease NotesVendor Advisory
- https://github.com/silverstripe/silverstripe-assets/commit/5f6a73b010c01587ffbfbPatchThird Party Advisory
- https://huntr.dev/bounties/90e17d95-9f2f-44eb-9f26-49fa13a41d5a/ExploitThird Party Advisory
- https://www.silverstripe.org/blog/tag/releaseRelease NotesVendor Advisory
- https://www.silverstripe.org/download/security-releases/Not ApplicableVendor Advisory
- https://www.silverstripe.org/download/security-releases/cve-2022-29858Release NotesVendor Advisory
FAQ
What is CVE-2022-29858?
CVE-2022-29858 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Silverstripe silverstripe/assets through 1.10 is vulnerable to improper access control that allows protected images to be published by changing an existing image short code on website content.
How severe is CVE-2022-29858?
CVE-2022-29858 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-29858?
Check the references section above for vendor advisories and patch information. Affected products include: Silverstripe Assets.