TYPO3-EXT-SA-2025-001: Account Takeover in extension "OpenID Connect Authentication" (oidc)
Moderate severity
GitHub Reviewed
Published
Jan 28, 2025
to the GitHub Advisory Database
•
Updated Mar 17, 2025
Description
Published to the GitHub Advisory Database
Jan 28, 2025
Reviewed
Jan 28, 2025
Published by the National Vulnerability Database
Mar 16, 2025
Last updated
Mar 17, 2025
Problem Description
A vulnerability in the account linking logic of the extension allows a pre-hijacking attack leading to Account Takeover. The attack can only be exploited if the following requirements are met:
Solution
An updated versions 4.0.0 is available from the TYPO3 extension manager, packagist and at
https://extensions.typo3.org/extension/download/oidc/4.0.0/zip
Users of the extension are advised to update the extension as soon as possible.
References