{"id":"GHSA-f777-f784-36gm","aliases":[],"url":"https://o3.security/vulnerability/GHSA-f777-f784-36gm","summary":"TYPO3 Security Misconfiguration in Install Tool Cookie","details":"It has been discovered that cookies created in the Install Tool are not hardened to be submitted only via HTTP. In combination with other vulnerabilities such as cross-site scripting it can lead to hijacking an active and valid session in the Install Tool.","published":"2024-06-07T19:52:43Z","modified":"2024-12-04T05:26:49.484217Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"typo3/cms","fixedVersion":"7.6.32"},{"ecosystem":"Packagist","name":"typo3/cms","fixedVersion":"8.7.21"},{"ecosystem":"Packagist","name":"typo3/cms","fixedVersion":"9.5.2"}],"fix":{"url":"https://github.com/TYPO3/typo3/commit/13328b0f74ac589a20b021db814dfa672581c26a","label":"TYPO3/typo3@13328b0"},"references":[{"type":"WEB","url":"https://github.com/TYPO3/typo3/commit/13328b0f74ac589a20b021db814dfa672581c26a"},{"type":"WEB","url":"https://github.com/TYPO3/typo3/commit/918e50e4d20d88c7e40ad3bb134267d07706b0b1"},{"type":"WEB","url":"https://github.com/TYPO3/typo3/commit/a5359491e3fb3164a6ba96a66c8e67fbb9971a4c"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/2018-12-11-4.yaml"},{"type":"PACKAGE","url":"https://github.com/TYPO3/typo3"},{"type":"WEB","url":"https://typo3.org/security/advisory/typo3-core-sa-2018-009"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-04T05:26:49.484217Z"}}