You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
TYPO3 is an open source PHP based web content management system. In versions prior to 10.4.33, 11.5.20, and 12.1.1, When users reset their password using the corresponding password recovery functionality, existing sessions for that particular user account were not revoked. This applied to both frontend user sessions and backend user sessions. This issue is patched in versions 10.4.33, 11.5.20, 12.1.1.
mend-bolt-for-githubbot
changed the title
CVE-2022-23502 (Medium) detected in typo3/cms-core-v10.4.32
CVE-2022-23502 (Medium) detected in typo3/cms-core-v10.4.32 - autoclosed
Jan 4, 2023
✔️ This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.
CVE-2022-23502 - Medium Severity Vulnerability
The core library of TYPO3.
Library home page: https://api.github.com/repos/TYPO3-CMS/core/zipball/0a64e284b7619f14cdb54a9216e65447ac2d6d2d
Dependency Hierarchy:
Found in base branch: master
TYPO3 is an open source PHP based web content management system. In versions prior to 10.4.33, 11.5.20, and 12.1.1, When users reset their password using the corresponding password recovery functionality, existing sessions for that particular user account were not revoked. This applied to both frontend user sessions and backend user sessions. This issue is patched in versions 10.4.33, 11.5.20, 12.1.1.
Publish Date: 2022-12-14
URL: CVE-2022-23502
Base Score Metrics:
Type: Upgrade version
Origin: GHSA-mgj2-q8wp-29rr
Release Date: 2022-12-14
Fix Resolution: v10.4.33,v11.5.20,v12.1.1
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: