In SilverStripe through 4.3.3, the previous fix for SS-2018-007 does not completely mitigate the risk of CSRF in GraphQL mutations,
References
Link | Resource |
---|---|
https://forum.silverstripe.org/c/releases | Release Notes Vendor Advisory |
https://www.silverstripe.org/blog/tag/release | Release Notes Vendor Advisory |
https://www.silverstripe.org/download/security-releases/ | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2020-02-19T16:28:06
Updated: 2020-02-19T16:28:06
Reserved: 2019-05-28T00:00:00
Link: CVE-2019-12437
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-02-19T17:15:11.013
Modified: 2020-02-20T13:14:34.927
Link: CVE-2019-12437
JSON object: View
Redhat Information
No data.
CWE