Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Smarty 4.3.4 is vulnerable #859

Open
henschi opened this issue Dec 18, 2024 · 3 comments
Open

Smarty 4.3.4 is vulnerable #859

henschi opened this issue Dec 18, 2024 · 3 comments

Comments

@henschi
Copy link

henschi commented Dec 18, 2024

The current smarty version in s9y is vulnerable.
See: GHSA-4rmg-292m-wg3w

@garvinhicking
Copy link
Member

Thanks for the report. Upgrading Smarty to the recent version is really a lot of work, and we're lacking person power to tackle this.

The vulnerability to my understand affects setups where people with restricted access would be able to escalate permissions. For the case of Serendipity, where no template editing is provided through GUI or other means to "normal" editors, we believe that only admins/maintainers of the site would be able to utilize this as an attack vector against themselves. So in the case of Serendipity, the security issue is of a lower impact than in applications providing the option to edit templates without already having full server access.

(Having said that, I fully support that an upgrade would be great and needed)

@henschi
Copy link
Author

henschi commented Dec 18, 2024

Thanks for your analysis.

@garvinhicking
Copy link
Member

All good! Also, I agree we can leave this open so we know it should be addressed and to be transparent

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants