製品・ソフトウェアに関する情報
October における認証の欠如に関する脆弱性
Title October における認証の欠如に関する脆弱性
Summary

October には、認証の欠如に関する脆弱性が存在します。 本脆弱性は、CVE-2020-26231 に対する修正が不完全だったことに起因する脆弱性です。

Possible impacts 情報を取得される、情報を改ざんされる、およびサービス運用妨害 (DoS) 状態にされる可能性があります。
Solution

ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。

Publication Date May 3, 2021, midnight
Registration Date Jan. 13, 2022, 6:07 p.m.
Last Update Jan. 13, 2022, 6:07 p.m.
CVSS3.0 : 警告
Score 5.2
Vector CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
CVSS2.0 : 警告
Score 4.4
Vector AV:L/AC:M/Au:N/C:P/I:P/A:P
Affected System
OctoberCMS
October 1.1.2 未満
October Build 472 1.0.472 未満
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
Change Log
No Changed Details Date of change
1 [2022年01月13日]
  掲載
Jan. 13, 2022, 6:07 p.m.

NVD Vulnerability Information
CVE-2021-21264
Summary

October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-26231 (fixed in 1.0.470/471 and 1.1.1) was discovered that has the same impact as CVE-2020-26231 & CVE-2020-15247. An authenticated backend user with the `cms.manage_pages`, `cms.manage_layouts`, or `cms.manage_partials` permissions who would **normally** not be permitted to provide PHP code to be executed by the CMS due to `cms.enableSafeMode` being enabled is able to write specific Twig code to escape the Twig sandbox and execute arbitrary PHP. This is not a problem for anyone that trusts their users with those permissions to normally write & manage PHP within the CMS by not having `cms.enableSafeMode` enabled, but would be a problem for anyone relying on `cms.enableSafeMode` to ensure that users with those permissions in production do not have access to write & execute arbitrary PHP. Issue has been patched in Build 472 (v1.0.472) and v1.1.2. As a workaround, apply https://github.com/octobercms/october/commit/f63519ff1e8d375df30deba63156a2fc97aa9ee7 to your installation manually if unable to upgrade to Build 472 or v1.1.2.

Publication Date May 4, 2021, 1:15 a.m.
Registration Date May 4, 2021, 10:02 a.m.
Last Update Nov. 21, 2024, 2:47 p.m.
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:* 1.0.471
cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:* 1.1.0 1.1.1
Related information, measures and tools
Common Vulnerabilities List