You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
On the original security issue (private) it was said the deprecate code was added for CMS 4 and in CMS 5 the EmbedShortcodeProvider_*.ss templates would hardcode the attributes
Deprecated code was added for CVE-2022-38724
https://github.com/silverstripe/silverstripe-framework/pull/10583/files#diff-d0d2867af6bff9ad7e4ced04d5491feea4b4efec408b6e96b37e4f5eb46914ecR37
On the original security issue (private) it was said the deprecate code was added for CMS 4 and in CMS 5 the EmbedShortcodeProvider_*.ss templates would hardcode the attributes
Currently this hasn't been done e.g. EmbedShortcoderProvider_video.ss is
We should either:
a) Hardcode attributes in templates and remove deprecated config/code
b) Undeprecate the attribute whitelist
Acceptance Criteria
PRs
The text was updated successfully, but these errors were encountered: