CVE-2022-31050
Insufficient Session Expiration in TYPO3's Admin Tool
6.0
MEDIUM
CVSS 3.1
EPSS 1.2%
描述
TYPO3 is an open source web content management system. Prior to versions 9.5.34 ELTS, 10.4.29, and 11.5.11, Admin Tool sessions initiated via the TYPO3 backend user interface had not been revoked even if the corresponding user account was degraded to lower permissions or disabled completely. This way, sessions in the admin tool theoretically could have been prolonged without any limit. TYPO3 versions 9.5.34 ELTS, 10.4.29, and 11.5.11 contain a fix for the problem.
如何修補 CVE-2022-31050
要修補 CVE-2022-31050,請將受影響套件升級到下列已修補版本。
- —升級至 9.5.35 或更新版本
- —升級至 10.4.29 或更新版本
- —升級至 9.5.35 或更新版本
CVE-2022-31050 正在被利用嗎?
低 — EPSS 為 1.2%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- >= 9.0.0, < 9.5.35, >= 10.0.0, < 10.4.29, >= 11.0.0, < 11.5.11
- >= 10.0.0, < 10.4.29
- >= 9.0.0, < 9.5.35
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.0 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L |