GHSA-qr5f-6fcv-w69q – typo3/cms
Package
Manager: composer
Name: typo3/cms
Vulnerable Version: >=8.0.0 <8.7.27 || >=9.0.0 <9.5.8
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:P/RL:O/RC:C
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS: N/A pctlN/A
Details
Typo3 Security Misconfiguration in Frontend Session Handling It has been discovered session data of properly authenticated and logged in frontend users is kept and transformed into an anonymous user session during the logout process. This way the next user using the same client application gains access to previous session data.
Metadata
Created: 2024-06-05T17:12:58Z
Modified: 2024-06-05T17:12:58Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-qr5f-6fcv-w69q/GHSA-qr5f-6fcv-w69q.json
CWE IDs: []
Alternative ID: N/A
Finding: F280
Auto approve: 1