CVE-2022-24740 is a high-severity authentication bypass vulnerability affecting Volto, the ReactJS frontend for Plone CMS, specifically versions 14.0.0-alpha.5 through 15.0.0-alpha.0. This flaw allows an authenticated attacker to hijack another user's session and gain control of their account by replacing their authentication cookie, particularly under high server load when using an outdated react-cookie library. The CVSS score of 7.5 (HIGH) reflects the potential for high impact on confidentiality, integrity, and availability, despite the high attack complexity. Currently, there is no public proof-of-concept, active exploitation, or significant community discussion, and it is not listed in the CISA KEV catalog. A fix is available in Volto 15.0.0-alpha.0, and a workaround involves manually upgrading the react-cookie package to version 4.1.1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 14.1.0, <= 14.10.0CPE matchmatch criteria | cpe:2.3:a:plone:volto:*:*:*:*:*:node.js:*:* | ||
14.0.0CPE matchmatch criteria | cpe:2.3:a:plone:volto:14.0.0:-:*:*:*:node.js:*:* | ||
14.0.0CPE matchmatch criteria | cpe:2.3:a:plone:volto:14.0.0:alpha10:*:*:*:node.js:*:* | ||
14.0.0CPE matchmatch criteria | cpe:2.3:a:plone:volto:14.0.0:alpha11:*:*:*:node.js:*:* | ||
14.0.0CPE matchmatch criteria | cpe:2.3:a:plone:volto:14.0.0:alpha12:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.