First published: Thu Jan 22 2009(Updated: )
Session fixation vulnerability in the authentication library in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote attackers to hijack web sessions via unspecified vectors related to (1) frontend and (2) backend authentication.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/typo3/cms | >=4.2.0<=4.2.3 | 4.2.4 |
composer/typo3/cms | >=4.1.0<=4.1.7 | 4.1.8 |
composer/typo3/cms | >=4.0.0<=4.0.9 | 4.0.10 |
TYPO3 | =4.0 | |
TYPO3 | =4.0.1 | |
TYPO3 | =4.0.2 | |
TYPO3 | =4.0.3 | |
TYPO3 | =4.0.4 | |
TYPO3 | =4.0.5 | |
TYPO3 | =4.0.6 | |
TYPO3 | =4.0.7 | |
TYPO3 | =4.0.8 | |
TYPO3 | =4.0.9 | |
TYPO3 | =4.1.0 | |
TYPO3 | =4.1.0-beta1 | |
TYPO3 | =4.1.0-rc1 | |
TYPO3 | =4.1.1 | |
TYPO3 | =4.1.2 | |
TYPO3 | =4.1.3 | |
TYPO3 | =4.1.4 | |
TYPO3 | =4.1.5 | |
TYPO3 | =4.1.6 | |
TYPO3 | =4.1.7 | |
TYPO3 | =4.2.0 | |
TYPO3 | =4.2.1 | |
TYPO3 | =4.2.2 | |
TYPO3 | =4.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0256 has a medium severity rating, as it allows remote attackers to hijack sessions.
To fix CVE-2009-0256, update TYPO3 to version 4.2.4, 4.1.8, or 4.0.10.
CVE-2009-0256 is a session fixation vulnerability affecting TYPO3 authentication.
Versions 4.0.0 to 4.0.9, 4.1.0 to 4.1.7, and 4.2.0 to 4.2.3 of TYPO3 are affected by CVE-2009-0256.
Yes, CVE-2009-0256 can be exploited by remote attackers to hijack sessions without requiring authentication.