{"id":"GHSA-vh7q-j8p5-2h4h","aliases":[],"url":"https://o3.security/vulnerability/GHSA-vh7q-j8p5-2h4h","summary":"silverstripe/framework sends passwords back to browsers under some circumstances","details":"Under some circumstances a form may populate a PasswordField with submitted data, reflecting submitted data back to a user. The user will only see their own submissions for password data, which is not considered best practice. We are not aware of data leaks to other users, devices or sessions.","published":"2024-05-27T23:21:53Z","modified":"2024-12-02T05:48:12.095322Z","cvss":{"score":3.5,"severity":"LOW","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"silverstripe/framework","fixedVersion":"3.7.0"},{"ecosystem":"Packagist","name":"silverstripe/framework","fixedVersion":"4.0.4"},{"ecosystem":"Packagist","name":"silverstripe/framework","fixedVersion":"4.1.1"}],"fix":{"url":"https://github.com/silverstripe/silverstripe-framework/commit/c28f411abd4837cdd9dbf87c4457976e678131cb","label":"silverstripe/silverstripe-framework@c28f411"},"references":[{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-framework/commit/c28f411abd4837cdd9dbf87c4457976e678131cb"},{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-framework/commit/f688bcb1a370e41df1b573a24fa3994b3895bacf"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/SS-2018-013-1.yaml"},{"type":"PACKAGE","url":"https://github.com/silverstripe/silverstripe-framework"},{"type":"WEB","url":"https://www.silverstripe.org/download/security-releases/ss-2018-013"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-02T05:48:12.095322Z"}}