{"id":"GHSA-hj78-p4h7-m5fv","summary":"TYPO3-EXT-SA-2025-001: Account Takeover in extension \"OpenID Connect Authentication\" (oidc)","details":"## Problem Description\nA vulnerability in the account linking logic of the extension allows a pre-hijacking attack leading to Account Takeover. The attack can only be exploited if the following requirements are met:\n\n- An attacker can anticipate the email address of the user.\n- An attacker can register a public frontend user account using that email address before the user's first OIDC login.\n- The IDP returns the field email containing the email address of the user\n\n## Solution\nAn updated versions 4.0.0 is available from the TYPO3 extension manager, packagist and at \nhttps://extensions.typo3.org/extension/download/oidc/4.0.0/zip\n\nUsers of the extension are advised to update the extension as soon as possible.","aliases":["CVE-2025-24856"],"modified":"2025-03-17T20:45:32.222405Z","published":"2025-01-28T19:15:44Z","database_specific":{"github_reviewed_at":"2025-01-28T19:15:44Z","nvd_published_at":"2025-03-16T04:15:14Z","cwe_ids":["CWE-288","CWE-348","CWE-639"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-24856"},{"type":"WEB","url":"https://github.com/xperseguers/t3ext-oidc/commit/877e09f6faf4c87bbb41233112ec7e30d3c902b3"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/causal/oidc/CVE-2025-24856.yaml"},{"type":"WEB","url":"https://typo3.org/security/advisory/typo3-ext-sa-2025-001"}],"affected":[{"package":{"name":"causal/oidc","ecosystem":"Packagist","purl":"pkg:composer/causal/oidc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"4.0.0"}]}],"versions":["v3.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/01/GHSA-hj78-p4h7-m5fv/GHSA-hj78-p4h7-m5fv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"}]}