
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-6164 affects SilverStripe through version 4.5.0, specifically involving the silverstripe/framework module. The vulnerability was discovered and disclosed on July 13, 2020. This security issue relates to information disclosure through a specific URL path that is configured by default in the framework (Vendor Advisory).
The vulnerability involves a specific URL path in the default configuration of the silverstripe/framework module that can reveal whether a domain is running a SilverStripe application. While the vulnerability does not disclose the specific version of the software, it does confirm the presence of a SilverStripe installation. The functionality on this URL path is restricted to CLI (Command Line Interface) context execution (NVD).
The primary impact of this vulnerability is limited to information disclosure, specifically revealing that a domain is running a SilverStripe application. As a secondary effect, the preconfigured path blocks the creation of other resources on this path, such as pages (Vendor Advisory).
The vulnerability has been rated as Low severity. The functionality on the affected URL path is limited to CLI context execution and is not known to present a vulnerability through web-based access (Vendor Advisory).
The issue has been fixed in silverstripe/framework versions 4.4.7, 4.5.4, and 4.6.0. Users are advised to upgrade to these or later versions to address the vulnerability (Vendor Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."