Project

General

Profile

Actions

Bug #91406

closed

"#1588095936: Missing referrer for Install Tool" in TYPO3 7.6.42 ELTS

Added by Dan Ilea over 4 years ago. Updated over 4 years ago.

Status:
Closed
Priority:
Should have
Category:
Security
Target version:
-
Start date:
2020-05-14
Due date:
% Done:

0%

Estimated time:
TYPO3 Version:
7
PHP Version:
Tags:
Complexity:
Is Regression:
Sprint Focus:

Description

Error "#1588095936: Missing referrer for Install Tool" occurs in TYPO3 7.6.42 ELTS and it seems to be related to the latest security update.

Reproduction steps:
  1. login to the TYPO3 backend
  2. unlock the "Install Tool"
  3. the error message appears

Tested on multiple servers & environments, does not seem to depend on PHP version or other factors.


Related issues 2 (0 open2 closed)

Related to TYPO3 Core - Bug #91414: After update from 9.5.16 to 9.5.17 I get an error 'Missing referrer for /main' in /typo3Closed2020-05-15

Actions
Related to TYPO3 Core - Bug #91420: MissingReferrerException TYPO3 v10.4.2Closed2020-05-16

Actions
Actions #1

Updated by Oliver Hader over 4 years ago

  • Assignee changed from Oliver Hader to Andreas Kienast
Actions #2

Updated by Oliver Hader over 4 years ago

  • Target version deleted (9.5.18 & 10.4.3)

Handing over to TYPO3 GmbH analyzing and handling ELTS packages.

Actions #3

Updated by Oliver Hader over 4 years ago

  • Related to Bug #91414: After update from 9.5.16 to 9.5.17 I get an error 'Missing referrer for /main' in /typo3 added
Actions #4

Updated by Oliver Hader over 4 years ago

  • Related to Bug #91420: MissingReferrerException TYPO3 v10.4.2 added
Actions #5

Updated by Oliver Hader over 4 years ago

  • Status changed from New to Needs Feedback

Please have a look in references issues to this ticket. The interesting aspects are

  • reverseProxy settings
  • custom Referrer-Policy HTTP headers (e.g. set to no-referrer)
Actions #6

Updated by Frank W Blank over 4 years ago

Update from 7.6.41 to 42

my mod_headers # Referrer-Policy
Header set Referrer-Policy "same-origin" # X-Frame-Options
Header always append X-Frame-Options SAMEORIGIN

also can not login to install Tool
headers were set in client

Actions #7

Updated by Neobe Parlot over 4 years ago

with 7.6.42 it's possible to excess the instaltool over /typo3/install/

For my project the problem is solved in 7.6.43, thanks for the fast release.

Actions #8

Updated by Andreas Kienast over 4 years ago

  • Status changed from Needs Feedback to Closed
Actions

Also available in: Atom PDF