silverstripe / silverstripe-admin

Silverstripe Admin Component
BSD 3-Clause "New" or "Revised" License
25 stars 91 forks source link

[CVE-2023-49783] Opt in to permission checks in bulk loaders #1654

Closed GuySartorelli closed 5 months ago

GuySartorelli commented 5 months ago

This should match https://github.com/silverstripe-security/silverstripe-admin/pull/17 exactly, except for the changed patch number in the framework constraint.

CI has already passed in the security repository. Any CI failures that are present there are expected and accounted for. This can be merged safely without waiting for CI to run again. CI will run after merging anyway, and is a safeguard prior to patching.

Issue