Skip to content

Commit

Permalink
Add CVE details for January 2025 Silverstripe CMS patches
Browse files Browse the repository at this point in the history
  • Loading branch information
GuySartorelli committed Jan 14, 2025
1 parent 0386c23 commit a44e21c
Show file tree
Hide file tree
Showing 3 changed files with 24 additions and 0 deletions.
8 changes: 8 additions & 0 deletions silverstripe/framework/CVE-2024-47605.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
title: "CVE-2024-47605 - XSS via insert media remote file oembed"
link: https://www.silverstripe.org/download/security-releases/cve-2024-47605
cve: CVE-2024-47605
branches:
5.3.x:
time: 2025-01-14 21:24:19
versions: ['<5.3.8']
reference: composer://silverstripe/framework
8 changes: 8 additions & 0 deletions silverstripe/framework/CVE-2024-53277.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
title: "CVE-2024-53277 - XSS in form messages"
link: https://www.silverstripe.org/download/security-releases/cve-2024-53277
cve: CVE-2024-53277
branches:
5.3.x:
time: 2025-01-14 21:24:36
versions: ['<5.3.8']
reference: composer://silverstripe/framework
8 changes: 8 additions & 0 deletions silverstripe/framework/SS-2024-002.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
title: "SS-2024-002 - Reflected Cross Site Scripting (XSS) in error message"
link: https://www.silverstripe.org/download/security-releases/ss-2024-002
cve: ~
branches:
5.3.x:
time: 2025-01-14 21:23:51
versions: ['<5.3.8']
reference: composer://silverstripe/framework

0 comments on commit a44e21c

Please sign in to comment.