HIGH8.5
GHSA-jj8r-p9f5-fmvv
Cross-site Scripting in TYPO3 extension
Quick fix
GHSA-jj8r-p9f5-fmvv — miniorange/miniorange-saml: upgrade to the fixed version with the command below.
composer require miniorange/miniorange-saml:^1.4.3Details
The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows XSS.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/miniorange/miniorange-saml
Introduced in:
0Fixed in: 1.4.3Fix
composer require miniorange/miniorange-saml:^1.4.3References
- https://nvd.nist.gov/vuln/detail/CVE-2021-36785[ADVISORY]
- https://github.com/miniOrangeDev/miniorange-saml-typo3-sso/commit/1fe2802267ffe1b48823d9d8b3a496c870a0af48[WEB]
- https://github.com/miniOrangeDev/miniorange-saml-typo3-sso[PACKAGE]
- https://typo3.org/help/security-advisories/security[WEB]
- https://typo3.org/security/advisory/typo3-ext-sa-2021-011[WEB]