<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 08:06:57 +0000</lastBuildDate>
    <item>
      <title>fkie_cve-2023-32302</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-32302</link>
      <description>&lt;p&gt;Rejected reason: Authoritative user requested CVE rejection&#13;
https://github.com/github/advisory-database/pull/2575#issuecomment-1745811653&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Rejected reason: Authoritative user requested CVE rejection&#13;
https://github.com/github/advisory-database/pull/2575#issuecomment-1745811653&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-32302</guid>
    </item>
    <item>
      <title>GHSA-36xx-7vf6-7mv3 — Silverstripe Framework: Members with no password can be created and bypass custom login forms</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-36xx-7vf6-7mv3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: silverstripe/framework&lt;/p&gt;
&lt;p&gt;When a new `Member` record was created in the cms it was possible to set a blank password. If an attacker knows the email address of the user with the blank password then they can attempt to log in using an empty password. The default member authenticator, login form and basic auth all require a non-empty password, however if a custom authentication method is used it may allow a successful login with the empty password. Starting with this release, blank passwords are no no longer allowed when members are created in the CMS. Programatically created `Member` records, such as those used in unit tests, still allow blank passwords. You may have some `Member` records in your system already which have empty passwords. To detect these, you can loop over all `Member` records with `Member::get()` and pass each record into the below method. It might be sensible to create a [`BuildTask`](https://api.silverstripe.org/5/SilverStripe/Dev/BuildTask.html) for this purpose.
  ```php
    private function memberHasBlankPassword(Member $member): bool
    {
        // skip default admin as this is created programatically
        if ($member-&amp;gt;isDefaultAdmin()) {
            return false;
        }
        // return true if a blank password is valid for this member
        $authenticator = new MemberAuthenticator();
        return $authenticator-&amp;gt;checkPassword($member, &amp;#39;&amp;#39;)-&amp;gt;isValid();
    }
  ```
  Once you have identified the records with empty passwords, it&amp;#39;s up to you how to handle this. The mos…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: silverstripe/framework&lt;/p&gt;
&lt;p&gt;When a new `Member` record was created in the cms it was possible to set a blank password. If an attacker knows the email address of the user with the blank password then they can attempt to log in using an empty password. The default member authenticator, login form and basic auth all require a non-empty password, however if a custom authentication method is used it may allow a successful login with the empty password. Starting with this release, blank passwords are no no longer allowed when members are created in the CMS. Programatically created `Member` records, such as those used in unit tests, still allow blank passwords. You may have some `Member` records in your system already which have empty passwords. To detect these, you can loop over all `Member` records with `Member::get()` and pass each record into the below method. It might be sensible to create a [`BuildTask`](https://api.silverstripe.org/5/SilverStripe/Dev/BuildTask.html) for this purpose.
  ```php
    private function memberHasBlankPassword(Member $member): bool
    {
        // skip default admin as this is created programatically
        if ($member-&amp;gt;isDefaultAdmin()) {
            return false;
        }
        // return true if a blank password is valid for this member
        $authenticator = new MemberAuthenticator();
        return $authenticator-&amp;gt;checkPassword($member, &amp;#39;&amp;#39;)-&amp;gt;isValid();
    }
  ```
  Once you have identified the records with empty passwords, it&amp;#39;s up to you how to handle this. The mos…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-36xx-7vf6-7mv3</guid>
    </item>
    <item>
      <title>gsd-2023-32302</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-32302</link>
      <description>gsd-2023-32302</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-32302</guid>
    </item>
  </channel>
</rss>
