PT-2020-16358 · Xmlsoft+1 · Libxml2+1
Victoria Lee
·
Published
2020-11-23
·
Updated
2024-03-06
·
CVE-2020-26229
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
TYPO3 versions 10.4.0 through 10.4.9
Description
The issue concerns XML external entity processing in RSS widgets, which is reasonable but theoretical, as it could not be reproduced with current PHP versions of supported and maintained system distributions. At least with libxml2 version 2.9, the processing of XML external entities is disabled by default and cannot be exploited. A valid backend user account is also required.
Recommendations
Update to TYPO3 version 10.4.10 to fix the problem described. As a temporary workaround, consider restricting access to RSS widgets until the update is applied. Additionally, ensure that libxml2 version 2.9 or later is used, as it disables XML external entity processing by default.
Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Typo3
Libxml2