PT-2022-17025 · Typo3 · Varnishcache Extension
Torben Hansen
·
Published
2022-02-19
·
Updated
2022-03-07
·
CVE-2022-24979
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Varnishcache extension versions prior to 2.0.1 for TYPO3
Description
An issue in the Edge Site Includes (ESI) content element renderer component of the Varnishcache extension for TYPO3 does not include an access check. This allows an unauthenticated user to render various content elements, resulting in insecure direct object reference (IDOR), with the potential of exposing internal content elements.
Recommendations
For versions prior to 2.0.1, update to version 2.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the ESI content element renderer component to minimize the risk of exploitation.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Varnishcache Extension