Description
The routes (aka Extbase Yaml Routes) extension before 2.1.1 for TYPO3, when CsrfTokenViewHelper is used, allows Sensitive Information Disclosure because a session identifier is unsafely present in HTML output.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2116 | The routes (aka Extbase Yaml Routes) extension before 2.1.1 for TYPO3, when CsrfTokenViewHelper is used, allows Sensitive Information Disclosure because a session identifier is unsafely present in HTML output. |
Github GHSA |
GHSA-vpw5-grxx-v396 | CSRF token exposure in TYPO3 extension |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T01:01:59.216Z
Reserved: 2021-07-19T00:00:00.000Z
Link: CVE-2021-36793
No data.
Status : Modified
Published: 2021-08-13T17:15:16.823
Modified: 2024-11-21T06:14:06.977
Link: CVE-2021-36793
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA