CVE-2013-7079: Input Validation
Open redirect vulnerability in the OpenID extension in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/friendsoftypo3/openidto a version that resolves this vulnerability.Fixed in 6.1.6 - Upgrade
Upgrade
composer/friendsoftypo3/openidto a version that resolves this vulnerability.Fixed in 6.0.11 - Upgrade
Upgrade
composer/friendsoftypo3/openidto a version that resolves this vulnerability.Fixed in 4.7.16 - Upgrade
Upgrade
composer/friendsoftypo3/openidto a version that resolves this vulnerability.Fixed in 4.5.31
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7079?
CVE-2013-7079 has a critical severity rating due to its capability to facilitate phishing attacks through open redirects.
How do I fix CVE-2013-7079?
To remediate CVE-2013-7079, upgrade to TYPO3 versions 4.5.31, 4.7.16, 6.0.11, or 6.1.6 or later.
Which TYPO3 versions are affected by CVE-2013-7079?
CVE-2013-7079 affects TYPO3 versions from 4.5.0 to 4.5.31, 4.7.0 to 4.7.16, 6.0.0 to 6.0.11, and 6.1.0 to 6.1.6.
What impact does CVE-2013-7079 have on users?
CVE-2013-7079 allows remote attackers to redirect users to arbitrary websites, increasing the risk of phishing attacks.
Is there a mitigation strategy for CVE-2013-7079?
Apart from upgrading to the fixed versions, users should implement strict input validation to mitigate the impact of CVE-2013-7079.