Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r4r6-j2j3-7pp5

Опубликовано: 09 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Contao: Remember-me tokens will not be cleared after a password change

Impact

When a front end member changes their password, the corresponding remember-me tokens are not removed.

Patches

Update to Contao 4.13.40.

Workarounds

Disable "Allow auto login" in the login module.

References

https://contao.org/en/security-advisories/remember-me-tokens-are-not-cleared-after-a-password-change

For more information

If you have any questions or comments about this advisory, open an issue in contao/contao.

Пакеты

Наименование

contao/core-bundle

composer
Затронутые версииВерсия исправления

< 4.13.40

4.13.40

EPSS

Процентиль: 44%
0.00212
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-384
CWE-613

Связанные уязвимости

CVSS3: 5.9
nvd
почти 2 года назад

Contao is an open source content management system. Prior to version 4.13.40, when a frontend member changes their password in the personal data or the password lost module, the corresponding remember-me tokens are not removed. If someone compromises an account and is able to get a remember-me token, changing the password would not be enough to reclaim control over the account. Version 4.13.40 contains a fix for the issue. As a workaround, disable "Allow auto login" in the login module.

EPSS

Процентиль: 44%
0.00212
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-384
CWE-613