OSV 1.4.0 · github-reviewed · 修改于 2021-11-19 21:46
发布时间
2020-11-24 03:48
GitHub 审查时间
2020-11-24 03:23
NVD 发布时间
2020-11-24 04:15
源文件
advisories/github-reviewed/2020/11/GHSA-xwjr-6fj7-fc6h/GHSA-xwjr-6fj7-fc6h.json
An attacker can exploit this vulnerability to read local files on an October CMS server. The vulnerability is exploitable by unauthenticated users via a specially crafted request.
Issue has been patched in Build 469 (v1.0.469) and v1.1.0.
Apply https://github.com/octobercms/library/commit/80aab47f044a2660aa352450f55137598f362aa4 to your installation manually if unable to upgrade to Build 469.
Reported by ka1n4t
If you have any questions or comments about this advisory: