{"id":"GHSA-592m-4533-rxq9","summary":"SilverStripe Folders migrated from 3.x may be unsafe to upload to","details":"In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default \"/Uploads\" folder instead. This affects installations which allowed upload folder protection via the optional silverstripe/secureassets module under 3.x. This module is installed and enabled by default on the Common Web Platform (CWP). The vulnerability only affects files uploaded after an upgrade to 4.x.","aliases":["BIT-silverstripe-2020-9280","CVE-2020-9280"],"modified":"2024-04-25T21:26:37.612295Z","published":"2022-05-24T17:15:19Z","database_specific":{"github_reviewed_at":"2024-04-25T21:06:35Z","nvd_published_at":"2020-04-15T21:15:00Z","cwe_ids":["CWE-434"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-9280"},{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-assets/commit/6779fd3c8c1c05a3db5035bf6e541c9483d161fc"},{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-userforms/commit/3bbad2044279ade5e5a5d0ae1822bafe479f8a26"},{"type":"WEB","url":"https://forum.silverstripe.org/c/releases"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/assets/CVE-2020-9280.yaml"},{"type":"PACKAGE","url":"https://github.com/silverstripe/silverstripe-framework"},{"type":"WEB","url":"https://www.silverstripe.org/download/security-releases"},{"type":"WEB","url":"https://www.silverstripe.org/download/security-releases/cve-2020-9280"}],"affected":[{"package":{"name":"silverstripe/framework","ecosystem":"Packagist","purl":"pkg:composer/silverstripe/framework"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"4.4.6"}]}],"versions":["4.0.0","4.0.1","4.0.1-rc1","4.0.2","4.0.3","4.0.4","4.0.5","4.0.6","4.0.7","4.1.0","4.1.0-rc1","4.1.0-rc2","4.1.1","4.1.2","4.1.3","4.1.4","4.1.5","4.2.0","4.2.0-beta1","4.2.1","4.2.2","4.2.3","4.2.4","4.2.5","4.3.0","4.3.0-rc1","4.3.1","4.3.2","4.3.3","4.3.4","4.3.5","4.4.0","4.4.0-rc1","4.4.1","4.4.2","4.4.3","4.4.4","4.4.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-592m-4533-rxq9/GHSA-592m-4533-rxq9.json"}},{"package":{"name":"silverstripe/userforms","ecosystem":"Packagist","purl":"pkg:composer/silverstripe/userforms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0"},{"fixed":"5.4.2"}]}],"versions":["5.0.0","5.0.1","5.0.2","5.1.0","5.1.1","5.2.0","5.2.1","5.2.2","5.3.0","5.3.1","5.3.2","5.3.3","5.4.0","5.4.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-592m-4533-rxq9/GHSA-592m-4533-rxq9.json"}},{"package":{"name":"silverstripe/assets","ecosystem":"Packagist","purl":"pkg:composer/silverstripe/assets"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"fixed":"1.4.7"}]}],"versions":["1.0.0","1.0.1","1.0.1-rc1","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.1.0","1.1.0-rc1","1.1.0-rc2","1.1.1","1.1.2","1.1.3","1.1.4","1.1.5","1.2.0","1.2.0-beta1","1.2.1","1.2.2","1.2.3","1.2.4","1.2.5","1.3.0","1.3.0-rc1","1.3.1","1.3.2","1.3.3","1.3.4","1.3.5","1.4.0","1.4.0-rc1","1.4.1","1.4.2","1.4.3","1.4.4","1.4.5","1.4.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-592m-4533-rxq9/GHSA-592m-4533-rxq9.json"}},{"package":{"name":"silverstripe/assets","ecosystem":"Packagist","purl":"pkg:composer/silverstripe/assets"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.5.0"},{"fixed":"1.5.2"}]}],"versions":["1.5.0","1.5.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-592m-4533-rxq9/GHSA-592m-4533-rxq9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}