Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GHSA-2g8p-j2r6-vqpj] October Cross-site Scripting vulnerability #2807

Conversation

daftspunk
Copy link

Updates

  • Affected products
  • Description
  • Severity
  • Source code location

Comments
This vulnerability is related to the October CMS installer (not October CMS the platform). These files are deleted when the installer finishes its process. This also was not responsibly disclosed to the October CMS team.

@github-actions github-actions bot changed the base branch from main to daftspunk/advisory-improvement-2807 October 2, 2023 07:02
@daftspunk
Copy link
Author

@daftspunk
Copy link
Author

Please resolve this using the following commit: octobercms/install@ef1225b

@shelbyc
Copy link
Contributor

shelbyc commented Oct 4, 2023

@daftspunk Thanks for following up with a fix commit! Before I make any changes to the advisory, is there any way for users of octobercms/october to update to the fix commit octobercms/install@ef1225b by updating the octobercms/october Composer package? If so, we want to list octobercms/october in the advisory. If they have to update in a way that has nothing to do with the octobercms/october Composer package, we'll note that the package that needs to be updated isn't in the Composer ecosystem.

@daftspunk
Copy link
Author

is there any way for users of octobercms/october to update to the fix commit ef1225b5596b7c2eb5ca3aa700a23e9f8acf387b by updating the octobercms/october Composer package?

Negative. The files are not included octobercms/october and the package is not part of the composer ecosystem.

Thank you for resolving this.

@advisory-database advisory-database bot merged commit a91d0c9 into daftspunk/advisory-improvement-2807 Oct 5, 2023
2 checks passed
@advisory-database advisory-database bot deleted the daftspunk-GHSA-2g8p-j2r6-vqpj branch October 5, 2023 13:20
@advisory-database
Copy link
Contributor

Hi @daftspunk! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants