VDB
Sign up
MEDIUM6.5

GHSA-gqmh-5xmq-3fhg

TYPO3 is vulnerable to Session Fixation

Quick fix

GHSA-gqmh-5xmq-3fhg — typo3/cms-install: upgrade to the fixed version with the command below.

composer require typo3/cms-install:^4.1.14

Details

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 is open to a session fixation attack which allows remote attackers to hijack a victim's session.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/typo3/cms-install
Introduced in: 0Fixed in: 4.1.14
Fixcomposer require typo3/cms-install:^4.1.14
Packagist/typo3/cms-install
Introduced in: 4.2.0Fixed in: 4.2.13
Fixcomposer require typo3/cms-install:^4.2.13
Packagist/typo3/cms-install
Introduced in: 4.3.0Fixed in: 4.3.4
Fixcomposer require typo3/cms-install:^4.3.4
Packagist/typo3/cms-install
Introduced in: 4.4.0Fixed in: 4.4.1
Fixcomposer require typo3/cms-install:^4.4.1

References