MEDIUM5.3
GHSA-c7xr-736p-29j3
TYPO3 is vulnerable to Insecure randomness in uniqid function
Quick fix
GHSA-c7xr-736p-29j3 — typo3/cms-install: upgrade to the fixed version with the command below.
composer require typo3/cms-install:^4.1.14Details
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness in the `uniqid` function.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/typo3/cms-install
Introduced in:
0Fixed in: 4.1.14Fix
composer require typo3/cms-install:^4.1.14Packagist/typo3/cms-install
Introduced in:
4.2.0Fixed in: 4.2.13Fix
composer require typo3/cms-install:^4.2.13Packagist/typo3/cms-install
Introduced in:
4.3.0Fixed in: 4.3.4Fix
composer require typo3/cms-install:^4.3.4Packagist/typo3/cms-install
Introduced in:
4.4.0Fixed in: 4.4.1Fix
composer require typo3/cms-install:^4.4.1References
- https://nvd.nist.gov/vuln/detail/CVE-2010-3666[ADVISORY]
- https://github.com/TYPO3/typo3/commit/302b35e714ca30ddb71ab36b9cbb2bea760a2f0e[WEB]
- https://github.com/TYPO3/typo3/commit/352d6066bf09137e86705bc060fd4ab3ba8f9191[WEB]
- https://github.com/TYPO3/typo3/commit/42324b30546b1e49fb16c916fc71cceb99ad9fd0[WEB]
- https://github.com/TYPO3/typo3/commit/f6d2e33cfab87c9e44eca275d6755be747e3cd7e[WEB]
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=590719[WEB]
- https://github.com/TYPO3-CMS/install[PACKAGE]
- https://security-tracker.debian.org/tracker/CVE-2010-3666[WEB]
- https://typo3.org/security/advisory/typo3-sa-2010-012/#Insecure_Randomness[WEB]