CVE-2020-26136
MEDIUM6.5EPSS 0.22%Authentication bypass in SilverStripe GraphQL
發布日:2021/6/10修改日:2024/2/17
描述
The GraphQL module accepts basic-auth as an authentication method by default. This can be used to bypass MFA authentication if the silverstripe/mfa module is installed, which is now a commonly installed module. A users password is still required though. Basic-auth has been removed as a default authentication method. If desired, it can be re-enabled by adding it to the authenticators key of a schema, or on SilverStripe\Graphql\Auth\Handler
受影響套件(2)
- Bitnami/silverstripefrom 0, < 4.6.0 | >= 4.6.0-rc1, <= 4.6.0-rc1
- Packagist/silverstripe/graphql>= 3.0.0, < 3.5.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
參考連結(7)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2020-26136
- WEBhttps://forum.silverstripe.org/c/releases
- WEBhttps://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/graphql/CVE-2020-26136.yaml
- WEBhttps://www.silverstripe.org/blog/tag/release
- WEBhttps://www.silverstripe.org/download/security-releases
- WEBhttps://www.silverstripe.org/download/security-releases/
- WEBhttps://www.silverstripe.org/download/security-releases/cve-2020-26136