VDB
Sign up
MEDIUM4.9

GHSA-wr3c-6c22-m9v6

Privilege Escalation in TYPO3 Neos

Quick fix

GHSA-wr3c-6c22-m9v6 — typo3/neos: upgrade to the fixed version with the command below.

composer require typo3/neos:^1.1.3

Details

It has been discovered that TYPO3 Neos is vulnerable to Privilege Escalation. Logged in editors could access, create and modify content nodes that exist in the workspace of other editors.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/typo3/neos
Introduced in: 1.1.0Fixed in: 1.1.3
Fixcomposer require typo3/neos:^1.1.3
Packagist/typo3/neos
Introduced in: 1.2.0Fixed in: 1.2.3
Fixcomposer require typo3/neos:^1.2.3

References