CVE-2021-21339
published 2021-03-23CVE-2021-21339: TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 user session…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.92%
55.7th percentile
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 user session identifiers were stored in cleartext - without processing of additional cryptographic hashing algorithms. This vulnerability cannot be exploited directly and occurs in combination with a chained attack - like for instance SQL injection in any other component of the system. This is fixed in versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| typo3 | cms | >= 10.0.0 < 10.4.14 | 10.4.14 |
| typo3 | cms | >= 11.0.0 < 11.1.1 | 11.1.1 |
| typo3 | cms | >= 9.0.0 < 9.5.25 | 9.5.25 |
| typo3 | cms-core | >= 10.0.0 < 10.4.14 | 10.4.14 |
| typo3 | cms-core | >= 11.0.0 < 11.1.1 | 11.1.1 |
| typo3 | cms-core | >= 6.2.0 < 6.2.57 | 6.2.57 |
| typo3 | cms-core | >= 7.0.0 < 7.6.51 | 7.6.51 |
| typo3 | cms-core | >= 8.0.0 < 8.7.40 | 8.7.40 |
| typo3 | cms-core | >= 9.0.0 < 9.5.25 | 9.5.25 |
| typo3 | typo3 | >= 10.0.0 < 10.4.14 | 10.4.14 |
| typo3 | typo3 | >= 11.0.0 < 11.1.1 | 11.1.1 |
| typo3 | typo3 | >= 6.2.0 < 6.2.57 | 6.2.57 |
| typo3 | typo3 | >= 7.0.0 < 7.6.51 | 7.6.51 |
| typo3 | typo3 | >= 8.0.0 < 8.7.40 | 8.7.40 |
| typo3 | typo3 | >= 9.0.0 < 9.5.25 | 9.5.25 |
| typo3 | typo3.cms | — | — |
| typo3 | typo3.cms | — | — |
| typo3 | typo3.cms | — | — |
| typo3 | typo3.cms | — | — |
| typo3 | typo3.cms | — | — |
| typo3 | typo3.cms | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Cleartext storage of session identifier
ghsa·2021-03-23
CVE-2021-21339 [MEDIUM] CWE-312 Cleartext storage of session identifier
Cleartext storage of session identifier
### Problem
User session identifiers were stored in cleartext - without processing of additional cryptographic hashing algorithms. This vulnerability cannot be exploited directly and occurs in combination with a chained attack - like for instance SQL injection in any other component of the system.
### Solution
Update to TYPO3 versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 that fix the problem described.
### Credits
Thanks to TYPO3 security team member Oliver Hader who reported this issue and to TYPO3 core & security team members Benni Mack & Oliver Hader who fixed the issue.
### References
* [TYPO3-CORE-SA-2021-006](https://typo3.org/security/advisory/typo3-core-sa-2021-006)
OSV
Cleartext storage of session identifier
osv·2021-03-23
CVE-2021-21339 [MEDIUM] Cleartext storage of session identifier
Cleartext storage of session identifier
### Problem
User session identifiers were stored in cleartext - without processing of additional cryptographic hashing algorithms. This vulnerability cannot be exploited directly and occurs in combination with a chained attack - like for instance SQL injection in any other component of the system.
### Solution
Update to TYPO3 versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 that fix the problem described.
### Credits
Thanks to TYPO3 security team member Oliver Hader who reported this issue and to TYPO3 core & security team members Benni Mack & Oliver Hader who fixed the issue.
### References
* [TYPO3-CORE-SA-2021-006](https://typo3.org/security/advisory/typo3-core-sa-2021-006)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/TYPO3/TYPO3.CMS/security/advisories/GHSA-qx3w-4864-94chhttps://packagist.org/packages/typo3/cms-corehttps://typo3.org/security/advisory/typo3-core-sa-2021-006https://github.com/TYPO3/TYPO3.CMS/security/advisories/GHSA-qx3w-4864-94chhttps://packagist.org/packages/typo3/cms-corehttps://typo3.org/security/advisory/typo3-core-sa-2021-006
2021-03-23
Published