CVE-2019-16409
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In the Versioned Files module through 2.0.3 for SilverStripe 3.x, unpublished versions of files are publicly exposed to anyone who can guess their URL. This guess could be highly informed by a basic understanding of the symbiote/silverstripe-versionedfiles source code. (Users who upgrade from SilverStripe 3.x to 4.x and had Versioned Files installed have no further need for this module, because the 4.x release has built-in versioning. However, nothing in the upgrade process automates the destruction of these insecure artefacts, nor alerts the user to the criticality of destruction.)
En el módulo Versioned Files versiones hasta 2.0.3 para SilverStripe versiones 3.x, las versiones no publicadas de archivos se exponen públicamente a cualquiera que pueda adivinar su URL. Esta suposición podría estar altamente informada para una comprensión básica del código fuente de symbiote/silverstripe-versionedfiles. (Los usuarios que actualizan SilverStripe versiones 3.x hasta 4.x y tenían instalado Versioned Files ya no necesitan este módulo, porque la versión 4.x posee versiones integradas. Sin embargo, nada en el proceso de actualización automatiza la destrucción de estos artefactos no seguros, ni alerta al usuario sobre la importancia de su destrucción).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-09-18 CVE Reserved
- 2019-09-26 CVE Published
- 2024-08-05 CVE Updated
- 2024-09-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/silverstripe/silverstripe-framework | Product | |
https://github.com/symbiote/silverstripe-versionedfiles | Product |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.silverstripe.org/download/security-releases/cve-2019-16409 | 2021-07-21 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Silverstripe Search vendor "Silverstripe" | Silverstripe Search vendor "Silverstripe" for product "Silverstripe" | >= 3.0.0 <= 3.7.4 Search vendor "Silverstripe" for product "Silverstripe" and version " >= 3.0.0 <= 3.7.4" | - |
Affected
| ||||||
Symbiote Search vendor "Symbiote" | Versionedfiles Search vendor "Symbiote" for product "Versionedfiles" | <= 2.0.3 Search vendor "Symbiote" for product "Versionedfiles" and version " <= 2.0.3" | silverstripe |
Affected
|