A vulnerability in the account linking logic of the extension allows a pre-hijacking attack leading to Account Takeover. The attack can only be exploited if the following requirements are met:
An updated versions 4.0.0 is available from the TYPO3 extension manager, packagist and at https://extensions.typo3.org/extension/download/oidc/4.0.0/zip
Users of the extension are advised to update the extension as soon as possible.
{
"nvd_published_at": "2025-03-16T04:15:14Z",
"severity": "MODERATE",
"github_reviewed": true,
"cwe_ids": [
"CWE-288",
"CWE-348",
"CWE-639"
],
"github_reviewed_at": "2025-01-28T19:15:44Z"
}