Publish GHSA-82vp-jr39-4j2j

This commit is contained in:
advisory-database[bot]
2024-05-30 18:24:32 +00:00
parent efd61c8763
commit 0b43a8ea50
@@ -0,0 +1,88 @@
{
"schema_version": "1.4.0",
"id": "GHSA-82vp-jr39-4j2j",
"modified": "2024-05-30T18:22:41Z",
"published": "2024-05-30T18:22:41Z",
"aliases": [
],
"summary": "TYPO3 Security Misconfiguration in Frontend Session Handling",
"details": "It has been discovered session data of properly authenticated and logged in frontend users is kept and transformed into an anonymous user session during the logout process. This way the next user using the same client application gains access to previous session data.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "typo3/cms-core"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "8.0.0"
},
{
"fixed": "8.7.27"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "typo3/cms-core"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "9.0.0"
},
{
"fixed": "9.5.8"
}
]
}
]
}
],
"references": [
{
"type": "WEB",
"url": "https://github.com/TYPO3-CMS/core/commit/c8c08ca0c26db02753c243e175a8a045628341b6"
},
{
"type": "WEB",
"url": "https://github.com/TYPO3-CMS/core/commit/fe43834075ae283c8cd91949e9f1dfd18b2d492f"
},
{
"type": "WEB",
"url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/2019-06-25-3.yaml"
},
{
"type": "PACKAGE",
"url": "https://github.com/TYPO3-CMS/core"
},
{
"type": "WEB",
"url": "https://typo3.org/security/advisory/typo3-core-sa-2019-018"
}
],
"database_specific": {
"cwe_ids": [
"CWE-488"
],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-05-30T18:22:41Z",
"nvd_published_at": null
}
}