Description
Due to the usage of an outdated version of the react-cookie library, under the circumstances of given a server high load, it is possible that a user could get his/her auth cookie replaced with the auth cookie from another user, effectively giving him full access to the other users account and privileges.
Recommendation
Update the @plone/volto
package to the latest compatible version. Followings are version details:
- Affected version(s): >= 14.0.0-alpha.6, <= 14.10.0
- Patched version(s): 15.0.0-alpha.0
References
Related Issues
- @plone/volto vulnerable to potential DoS by invoking specific URL by anonymous user - CVE-2025-61668
- seajs Cross-site Scripting vulnerability - CVE-2024-51091
- Deserialization of Untrusted Data in bson - CVE-2020-7610
- Cross-site scripting in bootstrap-select - CVE-2019-20921
- Tags:
- npm
- @plone/volto
Anything's wrong? Let us know Last updated on January 27, 2023