HIGH8.1
GHSA-f777-f784-36gm
TYPO3 Security Misconfiguration in Install Tool Cookie
Quick fix
GHSA-f777-f784-36gm — typo3/cms: upgrade to the fixed version with the command below.
composer require typo3/cms:^7.6.32Details
It has been discovered that cookies created in the Install Tool are not hardened to be submitted only via HTTP. In combination with other vulnerabilities such as cross-site scripting it can lead to hijacking an active and valid session in the Install Tool.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/TYPO3/typo3/commit/13328b0f74ac589a20b021db814dfa672581c26a[WEB]
- https://github.com/TYPO3/typo3/commit/918e50e4d20d88c7e40ad3bb134267d07706b0b1[WEB]
- https://github.com/TYPO3/typo3/commit/a5359491e3fb3164a6ba96a66c8e67fbb9971a4c[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/2018-12-11-4.yaml[WEB]
- https://github.com/TYPO3/typo3[PACKAGE]
- https://typo3.org/security/advisory/typo3-core-sa-2018-009[WEB]