TYPO3 Fixes Security Vulnerability in Image Controller
CVE-2024-34358
5.3MEDIUM
Key Information:
- Vendor
- Typo3
- Status
- Typo3
- Vendor
- CVE Published:
- 14 May 2024
Summary
TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the ShowImageController
(_eID tx_cms_showpic_
) lacks a cryptographic HMAC-signature on the frame
HTTP query parameter (e.g. /index.php?eID=tx_cms_showpic?file=3&...&frame=12345
). This allows adversaries to instruct the system to produce an arbitrary number of thumbnail images on the server side. TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, 13.1.1 fix the problem described.
Affected Version(s)
typo3 >= 9.0.0, < 9.5.48 < 9.0.0, 9.5.48
typo3 >= 10.0.0, < 10.4.45 < 10.0.0, 10.4.45
typo3 >= 11.0.0, < 11.5.37 < 11.0.0, 11.5.37
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved