First published: Mon Jul 31 2023(Updated: )
** REJECT ** Authoritative user requested CVE rejection https://github.com/github/advisory-database/pull/2575#issuecomment-1745811653
Credit: security-advisories@github.com security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Silverstripe Framework | >=5.0.0<5.0.13 | |
Silverstripe Framework | <4.3.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-32302 is a vulnerability in the Silverstripe Framework that allows an attacker to log in with an empty password.
CVE-2023-32302 affects Silverstripe Framework versions up to 4.3.14 and 5.0.13.
The severity of CVE-2023-32302 is high with a CVSS score of 8.1.
To fix CVE-2023-32302, update Silverstripe Framework to version 4.13.14 for versions up to 4.3.14, and version 5.0.13 for versions up to 5.0.13.
You can find more information about CVE-2023-32302 on the following sources: [GitHub commit](https://github.com/silverstripe/silverstripe-framework/commit/7b21b38ac4532d06565dfcefad50540ebd2b50f4), [GitHub security advisory](https://github.com/silverstripe/silverstripe-framework/security/advisories/GHSA-36xx-7vf6-7mv3), and [GitHub release](https://github.com/silverstripe/silverstripe-framework/releases/tag/4.13.14).