Description
Due to the usage of an outdated version of the react-cookie library, under the circumstances of given a server high load, it is possible that a user could get his/her auth cookie replaced with the auth cookie from another user, effectively giving him full access to the other users account and privileges.
Recommendation
Update the @plone/volto package to the latest compatible version. Followings are version details:
- Affected version(s): >= 14.0.0-alpha.6, <= 14.10.0
- Patched version(s): 15.0.0-alpha.0
References
Related Issues
- @plone/volto vulnerable to potential DoS by invoking specific URL by anonymous user - CVE-2025-61668
- Volto affected by possible DoS by invoking specific URL by anonymous user - CVE-2025-58047
- parse-server's session object properties can be updated by foreign user if object ID is known - CVE-2022-39225
- matrix-js-sdk subject to user impersonation due to key/device identifier confusion in SAS verification - CVE-2022-39250
- Tags:
- npm
- @plone/volto
Anything's wrong? Let us know Last updated on January 27, 2023