
Cloud Vulnerability DB
A community-led vulnerabilities database
A security misconfiguration vulnerability was discovered in TYPO3 CMS (GHSA-qr5f-6fcv-w69q) affecting the Frontend Session Handling component. The vulnerability was disclosed on June 25, 2019, affecting TYPO3 CMS versions 8.5.0-8.7.26 and 9.0.0-9.5.7. The issue was classified as a moderate severity vulnerability (TYPO3 Advisory, GitHub Advisory).
The vulnerability is related to session handling in the frontend component of TYPO3 CMS. The CVSS v3.0 score suggests a low severity with the following vector: AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N/E:F/RL:O/RC:C. The technical issue involves the retention and transformation of authenticated user session data into anonymous user sessions during the logout process (TYPO3 Advisory).
When exploited, this vulnerability allows subsequent users utilizing the same client application to gain access to previous session data of properly authenticated and logged-in frontend users after they log out. This creates a potential privacy and security risk for user session information (TYPO3 Advisory).
The vulnerability requires local access and user interaction to be exploited. The attack complexity is low, and no special privileges are required to execute the attack. The exploit status is confirmed with reliable proof of concept (TYPO3 Advisory).
The vulnerability has been patched in TYPO3 versions 8.7.27 and 9.5.8. For enhanced security, the system now purges existing session data when a frontend user logs out. Organizations can optionally disable this behavior by setting $GLOBALS['TYPO3_CONF_VARS']['SYS']['features']['security.frontend.keepSessionDataOnLogout'] = 1 either through the Install Tool or deployment techniques (TYPO3 Advisory).
The vulnerability was reported by Christian Ebert and fixed by TYPO3 security team member Oliver Hader. The TYPO3 community responded by implementing strong security defaults in the patched versions (TYPO3 Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."