Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo via maliciously crafted requests. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.
| Software | From | Fixed in |
|---|---|---|
| craftcms / craft_cms | 4.0.0.1 | 4.16.17 |
| craftcms / craft_cms | 5.0.1 | 5.8.21 |
| craftcms / craft_cms | 4.0.0 | 4.0.0.x |
| craftcms / craft_cms | 4.0.0-rc1 | 4.0.0-rc1.x |
| craftcms / craft_cms | 4.0.0-rc2 | 4.0.0-rc2.x |
| craftcms / craft_cms | 4.0.0-rc3 | 4.0.0-rc3.x |
| craftcms / craft_cms | 5.0.0 | 5.0.0.x |
| craftcms / craft_cms | 5.0.0-rc1 | 5.0.0-rc1.x |