Next upcoming security release for July

,

Hey everyone,

Next Wednesday, July 15, is going to be the day of the next planned security releases: Kirby 5.5.2 and a backported version 4.9.5.

Both releases will contain fixes for four vulnerabilities. Two of them concern path traversal in very specific deployment scenarios, affecting read access to JSON and media files stored on the server whose path is known. One vulnerability concerns information leaks via error messages. These three vulnerabilities can be exploited by unauthenticated visitors but will not affect all sites and will not cause direct harm. A fourth vulnerability only affects authenticated users and concerns permission checks for handling of temporary upload files.

You can already protect your sites against part of the impact by setting a secure content.salt option. https://getkirby.com/docs/guide/security#set-secure-random-values-for-the-content-salt-and-cookie-key

As in the previous months, we cannot provide detailed information about the vulnerabilities until the release. However feel free to ask if you have any questions about the release process.

We also have another announcement for you today: There will be no planned security release in August. So far we have not received any further vulnerability reports (knock on wood) and we also want to help you and your clients to have a well-deserved summer break without security patches. Independent from the skipped release we will still keep an eye on any critical vulnerabilities (according to CVSS scoring) and any exploited vulnerabilities that may come up. In these events we will still release short-term security fixes. But let’s hope that none of these will occur. In this case the next planned security release will be on September 16.