TYPO3 Fixes Security Vulnerability in Image Controller
CVE-2024-34358

5.3MEDIUM

Key Information:

Vendor
Typo3
Status
Typo3
Vendor
CVE Published:
14 May 2024

Summary

TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the ShowImageController (_eID tx_cms_showpic_) lacks a cryptographic HMAC-signature on the frame HTTP query parameter (e.g. /index.php?eID=tx_cms_showpic?file=3&...&frame=12345). This allows adversaries to instruct the system to produce an arbitrary number of thumbnail images on the server side. TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, 13.1.1 fix the problem described.

Affected Version(s)

typo3 >= 9.0.0, < 9.5.48 < 9.0.0, 9.5.48

typo3 >= 10.0.0, < 10.4.45 < 10.0.0, 10.4.45

typo3 >= 11.0.0, < 11.5.37 < 11.0.0, 11.5.37

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.