In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://www.silverstripe.org/download/security-releases/ | vendor advisory |
https://www.silverstripe.org/blog/tag/release | release notes vendor advisory |
https://forum.silverstripe.org/c/releases | release notes vendor advisory |
https://www.silverstripe.org/download/security-releases/cve-2020-26136 | exploit vendor advisory |