GHSA-93qh-5269-9wcf: High severity composer/statamic/cms vulnerability
Impact
When OAuth login is enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an existing user — potentially including a super admin — without their password. Exploitation requires OAuth to be explicitly enabled with such a provider.
Patches
Fixed in 5.74.1 and 6.24.0.
Workarounds
Only enable OAuth with providers that guarantee verified email addresses, or disable OAuth login.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/statamic/cmsto a version that resolves this vulnerability.Fixed in 6.24.0 - Upgrade
Upgrade
composer/statamic/cmsto a version that resolves this vulnerability.Fixed in 5.74.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.74.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.24.0 - Configuration
Disable OAuth login if you cannot ensure the provider guarantees verified email addresses.
OAuth login OAuth login enablement / provider usage = disable - Configuration
Only enable OAuth with providers that guarantee verified email addresses; otherwise disable OAuth login.
OAuth login OAuth provider selection (verified email guarantees) = allow only verified-email providers