CVE-2019-10641: Critical severity contao cms vulnerability
Published Apr 9, 2019
·Updated
Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.
Other sources
Existing sessions are not correctly invalidated when a user changes their password
Affected Software
10 affected componentsFixes available
composer/contao/core-bundle>=4.0.0, <4.4.37, >=4.5.0, <4.6.0, >=4.6.0, <4.7.0, >=4.7.0, <4.7.3
composer/contao/contao>=4.0.0, <4.4.37, >=4.5.0, <4.6.0, >=4.6.0, <4.7.0, >=4.7.0, <4.7.3
composer/contao/core>=3.0.0, <3.5.39
composer/contao/core>=3.0.0<3.5.39
3.5.39
composer/contao/core-bundle>=4.5.0<4.7.3
4.7.3
composer/contao/core-bundle>=4.0.0<4.4.37
4.4.37
composer/contao/contao>=4.5.0<4.7.3
4.7.3
composer/contao/contao>=4.0.0<4.4.37
4.4.37
Contao Contao CMS<3.5.39
Contao Contao CMS>=4.0.0<4.7.3
Event History
Apr 9, 2019
Advisory Published
10:24 AM
Apr 17, 2019
CVE Published
via MITRE·06:46 PM
Data Sourced
via MITRE·06:46 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-10641?
The severity of CVE-2019-10641 is critical with a score of 9.8.
2
Which versions of Contao are affected by CVE-2019-10641?
Contao versions 3.5.39 and below, as well as versions between 4.0.0 and 4.7.3, are affected by CVE-2019-10641.
3
How does CVE-2019-10641 impact existing sessions?
Existing sessions are not correctly invalidated when a user changes their password, leaving potential for unauthorized access.
4
What is the vulnerability in Contao?
Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.
5
How can I fix the vulnerability in Contao?
To fix the vulnerability, update Contao to version 3.5.39 or upgrade to Contao 4.7.3.