VDB
Sign up
MEDIUM5.3

GHSA-c7xr-736p-29j3

TYPO3 is vulnerable to Insecure randomness in uniqid function

Quick fix

GHSA-c7xr-736p-29j3 — typo3/cms-install: upgrade to the fixed version with the command below.

composer require typo3/cms-install:^4.1.14

Details

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness in the `uniqid` function.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/typo3/cms-install
Introduced in: 0Fixed in: 4.1.14
Fixcomposer require typo3/cms-install:^4.1.14
Packagist/typo3/cms-install
Introduced in: 4.2.0Fixed in: 4.2.13
Fixcomposer require typo3/cms-install:^4.2.13
Packagist/typo3/cms-install
Introduced in: 4.3.0Fixed in: 4.3.4
Fixcomposer require typo3/cms-install:^4.3.4
Packagist/typo3/cms-install
Introduced in: 4.4.0Fixed in: 4.4.1
Fixcomposer require typo3/cms-install:^4.4.1

References