craftcms/cms is vulnerable to Information Disclosure
55
Medium Risk
Craft CMS 5.11.0 fixes two GraphQL user-data authorization issues. GHSA-4w9w-3x96-7ghp allowed schemas limited to selected user groups to read unrelated users through native author, uploader, draft-creator, and revision-creator relations. GHSA-pcmv-c398-gc5m allowed public schemas with draft or revision access to expose creator usernames, names, email addresses, and addresses without corresponding user-query permission. A deployment within the vulnerable range may be exposed to either issue when the affected GraphQL fields are available.
You are affected if you are using a version that falls within the vulnerable range and expose GraphQL schemas that can query native user relations, drafts, or revisions without unrestricted user-data access.
craftcms/cms is vulnerable to Information Disclosure in versions 5.0.0 - 5.10.14.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.