- Notifications
You must be signed in to change notification settings - Fork1.4k
Security: getgrav/grav
Security
SECURITY.md
We are focusing our security updates on the following versions
Version | Supported |
---|---|
1.7.x | ✅ |
1.6.x | ❌ |
< 1.6 | ❌ |
NOTE: Please use the following guidelines when selecting aSeverity. Submitted advisories that are markedHigh orCritical that don't meet the guidelines below will be closed.
- CRITICAL - no account required, can modify content, or run malicious code or nefarious activity without any access.
- HIGH - publisher level account able to run malicious code or nefarious activity, or other high level security things.
- MODERATE - admin level account able to run malicious code or do nefarious things. other moderate security things.
- LOW - super admin level account able to run malicious code or do nefarious things. other minor security things.
Versions withdirect-install
command.
If you cannot update to the latest stable version available because, for example, your server does not meet the minimum PHP requirements, you can manually install a previous version by downloading the package from our Releases directory (https://github.com/getgrav/grav/releases).
Please contactsecurity@getgrav.org with a detailed explanation of the security issue found. If it appears to be a legitimate issues, please submit anadvisory via GitHub Security:https://github.com/getgrav/grav/security/advisories
NOTE: Please do not use 3rd party security issue reporting services, we like to keep everything in the GitHub ecosystem for easier manageability.
We do greatly appreciate your efforts to improve Grav, but unfortunately because we are a small open source project, wedo not have the resources to offer bounties for security issues found.
- Arbitrary File Read to Account TakeoverGHSA-f8v5-jmfh-pr69 published
May 15, 2024 byrhuksterHigh - File Upload Path TraversalGHSA-m7hx-hw6h-mqmc published
Mar 21, 2024 byrhuksterHigh - Server-Side Template Injection (SSTI) with Grav CMS security sandbox bypassGHSA-c9gp-64c4-2rrh published
Mar 21, 2024 byrhuksterHigh - Server Side Template Injection (SSTI)GHSA-qfv4-q44r-g7rv published
Mar 21, 2024 byrhuksterHigh - Server Side Template Injection (SSTI)GHSA-r6vw-8v8r-pmp4 published
Mar 21, 2024 byrhuksterHigh - Server Side Template Injection (SSTI) via Twig escape handlerGHSA-2m7x-c7px-hp58 published
Mar 21, 2024 byrhuksterHigh - Remote Code Execution by uploading a phar file using frontmatterGHSA-f6g2-h7qv-3m5v published
Mar 4, 2024 byrhuksterCritical - Server-side Template Injection (SSTI) mitigation bypass via incorrect filtering of double backslashGHSA-9436-3gmp-4f53 published
Jul 18, 2023 byrhuksterHigh - Server Side Template Injection (SSTI)GHSA-f9jf-4cp4-4fq5 published
Jun 14, 2023 byrhuksterCritical - Grav Server-side Template Injection (SSTI) via Insufficient Validation in filterFilterGHSA-96xv-rmwj-6p9w published
Jun 14, 2023 byrhuksterHigh