CVE-2019-10643: Critical severity contao cms vulnerability
Published Apr 9, 2019
·Updated
Confirming an opt-in token does not invalidate previous opt-in tokens
Other sources
Contao 4.7 allows Use of a Key Past its Expiration Date.
Affected Software
5 affected componentsFixes available
composer/contao/contao>=4.7.0, <4.7.3
composer/contao/core-bundle>=4.7.0, <4.7.3
composer/contao/core-bundle>=4.7.0<4.7.3
4.7.3
composer/contao/contao>=4.7.0<4.7.3
4.7.3
Contao Contao CMS=4.7.0
Event History
Apr 9, 2019
Advisory Published
12:21 PM
Apr 17, 2019
CVE Published
via MITRE·06:50 PM
Data Sourced
via MITRE·06:50 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-10643.
2
What is the severity of CVE-2019-10643?
The severity of CVE-2019-10643 is critical.
3
What does CVE-2019-10643 allow?
CVE-2019-10643 allows the use of a key past its expiration date.
4
What software is affected by CVE-2019-10643?
Contao 4.7 and Contao CMS 4.7.0 are affected by CVE-2019-10643.
5
How can I fix CVE-2019-10643?
To fix CVE-2019-10643, update Contao and Contao CMS to versions 4.7.4 or later.