GHSA-q45q-5233-229p
Dashboard / Vulnerabilities / GHSA-q45q-5233-229p
Summary: Authentication library in TYPO3 vulnerable to session fixation
Details: Session fixation vulnerability in the authentication library in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote attackers to hijack web sessions via unspecified vectors related to (1) frontend and (2) backend authentication.
References: https://nvd.nist.gov/vuln/detail/CVE-2009-0256, https://exchange.xforce.ibmcloud.com/vulnerabilities/48133, https://github.com/TYPO3/typo3, https://web.archive.org/web/20111210005350/http://www.securityfocus.com/bid/33376, http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-001, http://www.debian.org/security/2009/dsa-1711
Affected packages
Package
Name: typo3/cms
Purl: pkg:composer/typo3/cms
Affected ranges
Type: ECOSYSTEM
Events:
