SCA: security update for silverstripe/assets (GHSA-jgcf-rf45-2f8v)

medium Tenable Self-Hosted Container Security Plugin ID 440911

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to
2.4.5 and 3.0.0-rc1 through 3.1.2, images rendered in templates or otherwise accessed via DBFile::getURL()
or DBFile::getSourceURL() incorrectly add an access grant to the current session, which bypasses file
permissions. This usually happens when creating an image variant, for example using a manipulation method
like ScaleWidth() or Convert(). Note that if developers use DBFile directly in the $db configuration for a
DataObject class that doesn't subclass File, and if they were setting the visibility of those files to
"protected", those files will now need an explicit access grant to be accessed. If developers do not want
to explicitly provide access grants for these files in their apps (i.e. they want these files to be
accessible by default), they should use the "public" visibility. This issue has been fixed in versions
2.4.5 and 3.1.3. (CVE-2026-24749)

Solution

Update the silverstripe/assets library and its related packages to version 2.4.5 or later.

See Also

https://github.com/advisories/GHSA-jgcf-rf45-2f8v

Plugin Details

Severity: Medium

ID: 440911

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 4/27/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2026-24749

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 4/16/2026

Vulnerability Publication Date: 4/16/2026

Reference Information

CVE: CVE-2026-24749