{"id":"GHSA-rhf5-f553-xg82","summary":"Password exposure in concrete5/core","details":"Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) prior to version 8.5.7. Concrete CMS now checks to see if a file has a password in view_inline and, if it does, the file is not rendered.For version 8.5.6, the following mitigations were put in place a. restricting file types for view_inline to images only b. putting a warning in the file manager to advise users.","aliases":["CVE-2021-22951"],"modified":"2024-12-02T05:55:28.772544Z","published":"2021-11-23T18:18:16Z","database_specific":{"nvd_published_at":"2021-11-19T19:15:00Z","cwe_ids":["CWE-200","CWE-639"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-11-22T18:21:13Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-22951"},{"type":"WEB","url":"https://hackerone.com/reports/1102014"},{"type":"WEB","url":"https://documentation.concretecms.org/developers/introduction/version-history/857-release-notes"}],"affected":[{"package":{"name":"concrete5/core","ecosystem":"Packagist","purl":"pkg:composer/concrete5/core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.5.7"}]}],"versions":["8.2.0","8.2.0RC2","8.2.1","8.3.0","8.3.1","8.3.2","8.4.0","8.4.0RC3","8.4.0RC4","8.4.1","8.4.2","8.4.3","8.4.4","8.4.5","8.5.0","8.5.0RC1","8.5.0RC2","8.5.1","8.5.2","8.5.3","8.5.4","8.5.5","8.5.6","8.5.6RC1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/11/GHSA-rhf5-f553-xg82/GHSA-rhf5-f553-xg82.json"}}],"schema_version":"1.9.0"}