[TYPO3-dev] New 4.6.17 leads to #1359987599: jumpurl: Calculated juHash did not match the submitted juHash.

Alexander Bigga linux at bigga.de
Wed Mar 6 15:37:38 CET 2013


Hi Søren,

thank you. I found it and I understand it.

But don't use directmail newsletter modules or whatever.

I use only the feature "External Link" as page type setting to point to 
an external page (which might be in the same installation but with a 
different domain).

Without this jumpurl-redirect extension this doesn't work anymore. Is 
this really the intended behaviour of TYPO3 now? I cannot... really 
believe it.

Best,

Alexander
Am 06.03.2013 15:31, schrieb Søren Malling:
> Hi Alexander,
>
>  From the security bulletin
>
> =====
>
> If it is important that already distributed links  (e.g. by directmail
> newsletter module) are still working, you have to additionally:
>
>     - Install the provided extension
> (t3x<http://typo3.org/fileadmin/security-team/sa2013-01/jumpurl_redirect.t3x>
>     , zip<http://typo3.org/fileadmin/security-team/sa2013-01/jumpurl_redirect.zip>)
> which
>     covers the following cases:
>        - URLs which are present in pages or content elements are allowed to
>        be redirected to, even if the validation hash is missing or wrong.
>        - URLs which are present in newletters sent using the third party
>        module "directmail" are allowed to be redirected to, even if the
> validation
>        hash is missing or wrong.
>     - =====
>
> Regards
>
> Søren
> _______________________________________________
> TYPO3-dev mailing list
> TYPO3-dev at lists.typo3.org
> http://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-dev
>




More information about the TYPO3-dev mailing list