CVE-2019-16409 Details
Description
In the Versioned Files module through 2.0.3 for SilverStripe 3.x, unpublished versions of files are publicly exposed to anyone who can guess their URL. This guess could be highly informed by a basic understanding of the symbiote/silverstripe-versionedfiles source code. (Users who upgrade from SilverStripe 3.x to 4.x and had Versioned Files installed have no further need for this module, because the 4.x release has built-in versioning. However, nothing in the upgrade process automates the destruction of these insecure artefacts, nor alerts the user to the criticality of destruction.)
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/silverstripe/silverstripe-framework | CVE | ProductThird Party Advisory |
| https://github.com/symbiote/silverstripe-versionedfiles | CVE | ProductThird Party Advisory |
| https://www.silverstripe.org/download/security-releases/cve-2019-16409 | CVE | Vendor Advisory |
| https://github.com/silverstripe/silverstripe-framework | [email protected] | ProductThird Party Advisory |
| https://github.com/symbiote/silverstripe-versionedfiles | [email protected] | ProductThird Party Advisory |
| https://www.silverstripe.org/download/security-releases/cve-2019-16409 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| silverstripe silverstripe | >= 3.0.0, <= 3.7.4 |
CPE
Remediation
| |
| symbiote versionedfiles | <= 2.0.3 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jul 21, 2021 | CWE Remap | [email protected] |
| Oct 1, 2019 | Initial Analysis | [email protected] |