Skip to content

Commit

Permalink
Merge pull request #739 from creative-commoners/pulls/master/jan2025
Browse files Browse the repository at this point in the history
Add CVE details for January 2025 Silverstripe CMS patches
  • Loading branch information
glaubinix authored Jan 23, 2025
2 parents 0386c23 + a44e21c commit 034e882
Show file tree
Hide file tree
Showing 3 changed files with 24 additions and 0 deletions.
8 changes: 8 additions & 0 deletions silverstripe/framework/CVE-2024-47605.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
title: "CVE-2024-47605 - XSS via insert media remote file oembed"
link: https://www.silverstripe.org/download/security-releases/cve-2024-47605
cve: CVE-2024-47605
branches:
5.3.x:
time: 2025-01-14 21:24:19
versions: ['<5.3.8']
reference: composer://silverstripe/framework
8 changes: 8 additions & 0 deletions silverstripe/framework/CVE-2024-53277.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
title: "CVE-2024-53277 - XSS in form messages"
link: https://www.silverstripe.org/download/security-releases/cve-2024-53277
cve: CVE-2024-53277
branches:
5.3.x:
time: 2025-01-14 21:24:36
versions: ['<5.3.8']
reference: composer://silverstripe/framework
8 changes: 8 additions & 0 deletions silverstripe/framework/SS-2024-002.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
title: "SS-2024-002 - Reflected Cross Site Scripting (XSS) in error message"
link: https://www.silverstripe.org/download/security-releases/ss-2024-002
cve: ~
branches:
5.3.x:
time: 2025-01-14 21:23:51
versions: ['<5.3.8']
reference: composer://silverstripe/framework

0 comments on commit 034e882

Please sign in to comment.