Grav Product Security Update Advisory

Overview

 

An update has been released to address a vulnerability in Grav product. Users of affected versions are advised to update to the latest version.

 

Affected Products

 

Grav versions prior to 1.7.46

 

Resolved Vulnerabilities

 

Arbitrary file read vulnerability where a low-privileged user account with page editing privileges could read files on all servers using Twig syntax (CVE-2024-34082)

 

Vulnerability Patches

 

Vulnerability patches were made available in the latest update. Please follow the instructions on the Referenced Sites[1] to update to the latest Vulnerability Patches version.

Grav version 1.7.46

 

Referenced Sites

 

[1] CVE-2024-34082 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-34082

[2] Arbitrary File Read to Account Takeover

https://github.com/getgrav/grav/security/advisories/GHSA-f8v5-jmfh-pr69