Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links on protected pages, Contao sends the cookie header to external urls as well, the passed options for the http client are used for all requests. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, disable crawling protected pages.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2024-1172 | Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links on protected pages, Contao sends the cookie header to external urls as well, the passed options for the http client are used for all requests. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, disable crawling protected pages. |
![]() |
GHSA-9jh5-qf84-x6pr | Contao: Possible cookie sharing with external domains while checking protected pages for broken links |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 17 Jan 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Contao
Contao contao |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:* | |
Vendors & Products |
Contao
Contao contao |

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T00:48:49.584Z
Reserved: 2024-03-07T14:33:30.035Z
Link: CVE-2024-28235

Updated: 2024-05-23T19:01:23.008Z

Status : Analyzed
Published: 2024-04-09T16:15:07.863
Modified: 2025-01-17T15:42:02.050
Link: CVE-2024-28235

No data.

No data.