CVE-2009-0256: High severity Typo3 TYPO3 vulnerability
Session fixation vulnerability in the authentication library in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote attackers to hijack web sessions via unspecified vectors related to (1) frontend and (2) backend authentication.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/typo3/cmsto a version that resolves this vulnerability.Fixed in 4.2.4 - Upgrade
Upgrade
composer/typo3/cmsto a version that resolves this vulnerability.Fixed in 4.1.8 - Upgrade
Upgrade
composer/typo3/cmsto a version that resolves this vulnerability.Fixed in 4.0.10
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0256?
CVE-2009-0256 has a medium severity rating, as it allows remote attackers to hijack sessions.
How do I fix CVE-2009-0256?
To fix CVE-2009-0256, update TYPO3 to version 4.2.4, 4.1.8, or 4.0.10.
What type of vulnerability is CVE-2009-0256?
CVE-2009-0256 is a session fixation vulnerability affecting TYPO3 authentication.
Which versions of TYPO3 are affected by CVE-2009-0256?
Versions 4.0.0 to 4.0.9, 4.1.0 to 4.1.7, and 4.2.0 to 4.2.3 of TYPO3 are affected by CVE-2009-0256.
Can CVE-2009-0256 be exploited without authentication?
Yes, CVE-2009-0256 can be exploited by remote attackers to hijack sessions without requiring authentication.