PT-2024-40101 · Typo3 · Typo3

Published

2024-05-30

·

Updated

2024-05-30

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: TYPO3 (affected versions not specified)
Description: The issue concerns insecure deserialization in Extbase request handling. It requires a user-submitted payload to be signed with a corresponding HMAC-SHA1 using the sensitive TYPO3 encryptionKey as a secret. If the encryptionKey has been leaked, attackers could calculate the required HMAC-SHA1, allowing a malicious payload to be deserialized. This could happen if sensitive information was accidentally exposed in repositories or unprotected backup files. For successful exploitation, at least one Extbase plugin must be rendered in the frontend, and the encryptionKey must have been leaked.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

GHSA-5H5V-M596-R6RF

Affected Products

Typo3