GHSA-qh8c-7588-qfrvMediumCVSS 6.5
Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries
🔗 CVE IDs covered (1)
📋 Description
Impact
An authenticated Control Panel user could view content from entries they don't have permission to view, including entry content and custom field values, from any collection and including unpublished entries. No data could be modified.
Patches
This has been fixed in 5.74.1 and 6.24.0.
🎯 Affected products2
- composer/statamic/cms:< 5.74.1
- composer/statamic/cms:>= 6.0.0, < 6.24.0
🔗 References (6)
- https://github.com/statamic/cms/security/advisories/GHSA-qh8c-7588-qfrv
- https://github.com/statamic/cms/pull/14906
- https://github.com/statamic/cms/commit/6557f1d8a0d61c0e7ad9c9a8f42cb3288607495d
- https://github.com/statamic/cms/releases/tag/v5.74.1
- https://github.com/statamic/cms/releases/tag/v6.24.0
- https://github.com/advisories/GHSA-qh8c-7588-qfrv