VDB
Sign up
HIGH8.1

GHSA-954j-f27r-cj52

Cleartext storage of session identifier

Quick fix

GHSA-954j-f27r-cj52 — typo3/cms-core: upgrade to the fixed version with the command below.

composer require typo3/cms-core:^9.5.23

Details

User session identifiers were stored in cleartext - without processing of additional cryptographic hashing algorithms. This vulnerability cannot be exploited directly and occurs in combination with a chained attack - like for instance SQL injection in any other component of the system.

### Solution Update to TYPO3 versions 9.5.23 or 10.4.10 that fix the problem described.

### Credits Thanks to TYPO3 security team member Helmut Hummel who reported this issue and to TYPO3 core & security team members Benni Mack & Oliver Hader as well as TYPO3 contributor Markus Klein who fixed the issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/typo3/cms-core
Introduced in: 9.0.0Fixed in: 9.5.23
Fixcomposer require typo3/cms-core:^9.5.23
Packagist/typo3/cms-core
Introduced in: 10.0.0Fixed in: 10.4.10
Fixcomposer require typo3/cms-core:^10.4.10
Packagist/typo3/cms-core
Introduced in: 8.7.0Fixed in: 8.7.38
Fixcomposer require typo3/cms-core:^8.7.38
Packagist/typo3/cms
Introduced in: 10.0.0Fixed in: 10.4.10
Fixcomposer require typo3/cms:^10.4.10
Packagist/typo3/cms
Introduced in: 9.0.0Fixed in: 9.5.23
Fixcomposer require typo3/cms:^9.5.23
Packagist/typo3/cms
Introduced in: 8.7.0Fixed in: 8.7.38
Fixcomposer require typo3/cms:^8.7.38

References