CVE-2021-21338
Open Redirection in Login Handling
Description
### Problem It has been discovered that Login Handling is susceptible to open redirection which allows attackers redirecting to arbitrary content, and conducting phishing attacks. No authentication is required in order to exploit this vulnerability. ### Solution Update to TYPO3 versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 that fix the problem described. ### Credits Thanks to Alexander Kellner who reported this issue and to TYPO3 security team member Torben Hansen who fixed the issue. ### References * [TYPO3-CORE-SA-2021-001](https://typo3.org/security/advisory/typo3-core-sa-2021-001)
How to fix CVE-2021-21338
To remediate CVE-2021-21338, upgrade the affected package to a fixed version below.
- —upgrade to 6.2.57 or later
- —upgrade to 10.4.14 or later
- —upgrade to 6.2.57 or later
Is CVE-2021-21338 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- >= 6.2.0, < 6.2.57, >= 7.0.0, < 7.6.51, >= 8.0.0, < 8.7.40, >= 9.0.0, < 9.5.25, >= 10.0.0, < 10.4.14, >= 11.0.0, < 11.1.1
- >= 10.0.0, < 10.4.14
- >= 6.2.0, < 6.2.57
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |