Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links on protected pages, Contao sends the cookie header to external urls as well, the passed options for the http client are used for all requests. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, disable crawling protected pages.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1172 | Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links on protected pages, Contao sends the cookie header to external urls as well, the passed options for the http client are used for all requests. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, disable crawling protected pages. |
Github GHSA |
GHSA-9jh5-qf84-x6pr | Contao: Possible cookie sharing with external domains while checking protected pages for broken links |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 17 Jan 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Contao
Contao contao |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Contao
Contao contao |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T00:48:49.584Z
Reserved: 2024-03-07T14:33:30.035Z
Link: CVE-2024-28235
Updated: 2024-05-23T19:01:23.008Z
Status : Analyzed
Published: 2024-04-09T16:15:07.863
Modified: 2025-01-17T15:42:02.050
Link: CVE-2024-28235
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA