GHSA-82vp-jr39-4j2j – typo3/cms-core
Package
Manager: composer
Name: typo3/cms-core
Vulnerable Version: >=8.0.0 <8.7.27 || >=9.0.0 <9.5.8
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS: N/A pctlN/A
Details
TYPO3 Security Misconfiguration in Frontend Session Handling It has been discovered session data of properly authenticated and logged in frontend users is kept and transformed into an anonymous user session during the logout process. This way the next user using the same client application gains access to previous session data.
Metadata
Created: 2024-05-30T18:22:41Z
Modified: 2024-05-30T18:22:41Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-82vp-jr39-4j2j/GHSA-82vp-jr39-4j2j.json
CWE IDs: ["CWE-488"]
Alternative ID: N/A
Finding: F076
Auto approve: 1