PKSA-hq3k-cthz-b9zn Security Advisory
-
[LOW] Craft CMS: Authorized asset "preview file" requests bypass allows users without asset access to retrieve private preview metadata
PKSA-hq3k-cthz-b9zn GHSA-44px-qjjc-xrhq
Affected package: craftcms/cms
Affected version: >=4.0.0-RC1,<=4.17.7|>=5.0.0-RC1,<=5.9.13
Reported by:
GitHub