← Back

CVE-2022-24740

nvd nist
Published: Mar 14, 2022Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.6 / Impact: 5.9
Source: NVD

Description

Volto is a ReactJS-based frontend for the Plone Content Management System. Between versions 14.0.0-alpha.5 and 15.0.0-alpha.0, a user could have their authentication cookie replaced with an authentication cookie from another user, effectively giving them control of the other user's account and privileges. This occurs when using an outdated version of the `react-cookie` library and a server is under high load. A proof of concept does not currently exist, but it is possible for this issue to occur in the wild. The patch and fix is present in Volto 15.0.0-alpha.0. As a workaround, one may manually upgrade the `react-cookie` package to 4.1.1 and then override all Volto components that use this library.

Affected (41)

Products: Plone: Volto
1 product
Volto
Configuration A
41 vulnerable
Vulnerable SoftwareAffected Versions
Plone
From 14.1.0 to 14.10.0
Version 14.0.0
Version 14.0.0 alpha10
Version 14.0.0 alpha11
Version 14.0.0 alpha12
Version 14.0.0 alpha13
Version 14.0.0 alpha14
Version 14.0.0 alpha15
Version 14.0.0 alpha16
Version 14.0.0 alpha17
Version 14.0.0 alpha18
Version 14.0.0 alpha19
Version 14.0.0 alpha20
Version 14.0.0 alpha21
Version 14.0.0 alpha22
Version 14.0.0 alpha23
Version 14.0.0 alpha24
Version 14.0.0 alpha25
Version 14.0.0 alpha26
Version 14.0.0 alpha27
Version 14.0.0 alpha28
Version 14.0.0 alpha29
Version 14.0.0 alpha30
Version 14.0.0 alpha31
Version 14.0.0 alpha32
Version 14.0.0 alpha33
Version 14.0.0 alpha34
Version 14.0.0 alpha35
Version 14.0.0 alpha36
Version 14.0.0 alpha37
Version 14.0.0 alpha38
Version 14.0.0 alpha39
Version 14.0.0 alpha40
Version 14.0.0 alpha41
Version 14.0.0 alpha42
Version 14.0.0 alpha43
Version 14.0.0 alpha6
Version 14.0.0 alpha7
Version 14.0.0 alpha8
Version 14.0.0 alpha9
Version 15.0.0 alpha0

References (4)

Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.