Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links on protected pages, Contao sends the cookie header to external urls as well, the passed options for the http client are used for all requests. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, disable crawling protected pages.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-04-09T15:50:56.531Z

Updated: 2024-08-02T00:48:49.584Z

Reserved: 2024-03-07T14:33:30.035Z

Link: CVE-2024-28235

cve-icon Vulnrichment

Updated: 2024-05-23T19:01:23.008Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-09T16:15:07.863

Modified: 2024-11-21T09:06:03.783

Link: CVE-2024-28235

cve-icon Redhat

No data.