SCA: security update for silverstripe/graphql (GHSA-jgph-w8rh-xf5p)

medium Tenable Cloud Security Plugin ID 416359

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0
prior to 4.3.7 and 5.0.0 prior to 5.1.3, `canView` permission checks are bypassed for ORM data in
paginated GraphQL query results where the total number of records is greater than the number of records
per page. Note that this also affects GraphQL queries which have a limit applied, even if the query isn’t
paginated per se. This has been fixed in versions 4.3.7 and 5.1.3 by ensuring no new records are pulled in
from the database after performing `canView` permission checks for each page of results. This may result
in some pages in the query results having less than the maximum number of records per page even when there
are more pages of results. This behavior is consistent with how pagination works in other areas of
Silverstripe CMS, such as in `GridField`, and is a result of having to perform permission checks in PHP
rather than in the database directly. One may disable these permission checks by disabling the
`CanViewPermission` plugin. (CVE-2023-44401)

See Also

https://github.com/advisories/GHSA-jgph-w8rh-xf5p

Plugin Details

Severity: Medium

ID: 416359

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2023-44401

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/23/2024

Vulnerability Publication Date: 1/23/2024

Reference Information

CVE: CVE-2023-44401

cwe: CWE-863