github.com
https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/SS-2018-013-1.yaml GHSA-VH7Q-J8P5-2H4H
silverstripe/framework sends passwords back to browsers under some circumstances
Description
Under some circumstances a form may populate a PasswordField with submitted data, reflecting submitted data back to a user. The user will only see their own submissions for password data, which is not considered best practice. We are not aware of data leaks to other users, devices or sessions.
Description source: GitHub Advisory
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
silverstripe/frameworkBrowse Packagist / silverstripe/framework | GitHub Advisory | 3.5.5-rc1 to < 3.7.0 · Fixed in 3.7.0 | affected |
| 4.0.3-rc1 to < 4.0.4 · Fixed in 4.0.4 | affected | ||
| 4.1.0-rc1 to < 4.1.1 · Fixed in 4.1.1 | affected |
References
5github.com
https://github.com/silverstripe/silverstripe-framework github.com
https://github.com/silverstripe/silverstripe-framework/commit/c28f411abd4837cdd9dbf87c4457976e678131cb github.com
https://github.com/silverstripe/silverstripe-framework/commit/f688bcb1a370e41df1b573a24fa3994b3895bacf silverstripe.org
https://www.silverstripe.org/download/security-releases/ss-2018-013