Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links on protected pages, Contao sends the cookie header to external urls as well, the passed options for the http client are used for all requests. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, disable crawling protected pages.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-04-09T15:50:56.531Z
Updated: 2024-08-02T00:48:49.584Z
Reserved: 2024-03-07T14:33:30.035Z
Link: CVE-2024-28235
Vulnrichment
Updated: 2024-05-23T19:01:23.008Z
NVD
Status : Awaiting Analysis
Published: 2024-04-09T16:15:07.863
Modified: 2024-11-21T09:06:03.783
Link: CVE-2024-28235
Redhat
No data.