CRITICAL9.8
GHSA-vcgg-hp4r-87gx
Contao Does Not Invalidate Existing Sessions When Password Changes
Quick fix
GHSA-vcgg-hp4r-87gx — contao/contao: upgrade to the fixed version with the command below.
composer require contao/contao:^4.4.37Details
Security researcher Ali Razzaq has discovered that existing sessions are not correctly invalidated when a user changes their password in the backend or frontend.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/contao/contao
Introduced in:
4.0.0Fixed in: 4.4.37Fix
composer require contao/contao:^4.4.37Packagist/contao/core-bundle
Introduced in:
4.0.0Fixed in: 4.4.37Fix
composer require contao/core-bundle:^4.4.37Packagist/contao/core-bundle
Introduced in:
4.5.0Fixed in: 4.7.3Fix
composer require contao/core-bundle:^4.7.3References
- https://nvd.nist.gov/vuln/detail/CVE-2019-10641[ADVISORY]
- https://github.com/contao/contao/commit/74c7dfafa0dfa5363a9463b486522d5d526e28fe[WEB]
- https://github.com/contao/contao/commit/b92e27bc7c9e59226077937f840c74ffd0f672e8[WEB]
- https://github.com/contao/core/commit/119a1b5bd9e62d27ca2838727084d04f3b7fcd32[WEB]
- https://contao.org/en/news/security-vulnerability-cve-2019-10641.html[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/contao/CVE-2019-10641.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/core-bundle/CVE-2019-10641.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/core/CVE-2019-10641.yaml[WEB]