GHSA-82vp-jr39-4j2j

Suggest an improvement
Source
https://github.com/advisories/GHSA-82vp-jr39-4j2j
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-82vp-jr39-4j2j/GHSA-82vp-jr39-4j2j.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-82vp-jr39-4j2j
Published
2024-05-30T18:22:41Z
Modified
2024-12-05T05:56:53Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N CVSS Calculator
Summary
TYPO3 Security Misconfiguration in Frontend Session Handling
Details

It has been discovered session data of properly authenticated and logged in frontend users is kept and transformed into an anonymous user session during the logout process. This way the next user using the same client application gains access to previous session data.

Database specific
{
    "cwe_ids":  [
        "CWE-488"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2024-05-30T18:22:41Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

Packagist / typo3/cms-core

Package

Name
typo3/cms-core
Purl
pkg:composer/typo3/cms-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
8.0.0
Fixed
8.7.27

Affected versions

v8.*
v8.7.7
v8.7.8
v8.7.9
v8.7.10
v8.7.11
v8.7.12
v8.7.13
v8.7.14
v8.7.15
v8.7.16
v8.7.17
v8.7.18
v8.7.19
v8.7.20
v8.7.21
v8.7.22
v8.7.23
v8.7.24
v8.7.25
v8.7.26

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-82vp-jr39-4j2j/GHSA-82vp-jr39-4j2j.json"

Packagist / typo3/cms-core

Package

Name
typo3/cms-core
Purl
pkg:composer/typo3/cms-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
9.0.0
Fixed
9.5.8

Affected versions

v9.*
v9.0.0
v9.1.0
v9.2.0
v9.2.1
v9.3.0
v9.3.1
v9.3.2
v9.3.3
v9.4.0
v9.5.0
v9.5.1
v9.5.2
v9.5.3
v9.5.4
v9.5.5
v9.5.6
v9.5.7

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-82vp-jr39-4j2j/GHSA-82vp-jr39-4j2j.json"