logo

GHSA-qr5f-6fcv-w69q typo3/cms

Package

Manager: composer
Name: typo3/cms
Vulnerable Version: >=8.0.0 <8.7.27 || >=9.0.0 <9.5.8

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:P/RL:O/RC:C

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

EPSS: N/A pctlN/A

Details

Typo3 Security Misconfiguration in Frontend Session Handling It has been discovered session data of properly authenticated and logged in frontend users is kept and transformed into an anonymous user session during the logout process. This way the next user using the same client application gains access to previous session data.

Metadata

Created: 2024-06-05T17:12:58Z
Modified: 2024-06-05T17:12:58Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-qr5f-6fcv-w69q/GHSA-qr5f-6fcv-w69q.json
CWE IDs: []
Alternative ID: N/A
Finding: F280
Auto approve: 1