Skip to content

Commit 8b986a0

Browse files
committed
Merge branch 'advisory/GHSA-x76w-8c62-48mg' into 4.x
2 parents bb2a150 + ed56049 commit 8b986a0

2 files changed

Lines changed: 4 additions & 1 deletion

File tree

CHANGELOG.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
## Unreleased
44

55
- The `PDO::MYSQL_ATTR_MULTI_STATEMENTS` attribute is no longer set by default for database connections. ([#18474](https://github.com/craftcms/cms/issues/18474))
6-
- Fixed [low-severity](https://github.com/craftcms/cms/security/policy#severity--remediation) information disclosure vulnerabilities. (GHSA-5pgf-h923-m958, GHSA-vgjg-248p-rfm2)
6+
- Fixed [low-severity](https://github.com/craftcms/cms/security/policy#severity--remediation) information disclosure vulnerabilities. (GHSA-5pgf-h923-m958, GHSA-vgjg-248p-rfm2, GHSA-x76w-8c62-48mg)
77
- Fixed a [moderate-severity](https://github.com/craftcms/cms/security/policy#severity--remediation) access control vulnerability. (GHSA-6mrr-q3pj-h53w)
88
- Fixed [moderate-severity](https://github.com/craftcms/cms/security/policy#severity--remediation) information disclosure vulnerabilities. (GHSA-3pvf-vxrv-hh9c, GHSA-5pgf-h923-m958)
99

src/controllers/AssetsController.php

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -143,6 +143,9 @@ public function actionPreviewThumb(): Response
143143
throw new BadRequestHttpException("Invalid asset ID: $assetId");
144144
}
145145

146+
$this->requireVolumePermissionByAsset('editImages', $asset);
147+
$this->requirePeerVolumePermissionByAsset('editPeerImages', $asset);
148+
146149
return $this->asJson([
147150
'img' => $asset->getPreviewThumbImg($width, $height),
148151
]);

0 commit comments

Comments
 (0)