VDB
Sign up
MEDIUM4.2

GHSA-hj78-p4h7-m5fv

TYPO3-EXT-SA-2025-001: Account Takeover in extension "OpenID Connect Authentication" (oidc)

Quick fix

GHSA-hj78-p4h7-m5fv — causal/oidc: upgrade to the fixed version with the command below.

composer require causal/oidc:^4.0.0

Details

## Problem Description A vulnerability in the account linking logic of the extension allows a pre-hijacking attack leading to Account Takeover. The attack can only be exploited if the following requirements are met:

- An attacker can anticipate the email address of the user. - An attacker can register a public frontend user account using that email address before the user's first OIDC login. - The IDP returns the field email containing the email address of the user

## Solution An updated versions 4.0.0 is available from the TYPO3 extension manager, packagist and at https://extensions.typo3.org/extension/download/oidc/4.0.0/zip

Users of the extension are advised to update the extension as soon as possible.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/causal/oidc
Introduced in: 3.0.0Fixed in: 4.0.0
Fixcomposer require causal/oidc:^4.0.0

References