Authentication library in TYPO3 vulnerable to session fixation
High severity
GitHub Reviewed
Published
May 2, 2022
to the GitHub Advisory Database
•
Updated Jan 23, 2024
Package
Affected versions
>= 4.0.0, <= 4.0.9
>= 4.1.0, <= 4.1.7
>= 4.2.0, <= 4.2.3
Patched versions
4.0.10
4.1.8
4.2.4
Description
Published by the National Vulnerability Database
Jan 22, 2009
Published to the GitHub Advisory Database
May 2, 2022
Last updated
Jan 23, 2024
Reviewed
Jan 23, 2024
Session fixation vulnerability in the authentication library in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote attackers to hijack web sessions via unspecified vectors related to (1) frontend and (2) backend authentication.
References