Vulnerabilities/

Sudden swap of user auth tokens in Volto

Severity:
Medium

Description

Due to the usage of an outdated version of the react-cookie library, under the circumstances of given a server high load, it is possible that a user could get his/her auth cookie replaced with the auth cookie from another user, effectively giving him full access to the other users account and privileges.

Recommendation

Update the @plone/volto package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@plone/volto
Anything's wrong? Let us know Last updated on January 27, 2023

This issue is available in SmartScanner Professional

See Pricing