PT-2024-40321 · Typo3 · Typo3
Published
2024-06-07
·
Updated
2024-06-07
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TYPO3 (affected versions not specified)
Description
The issue concerns insecure deserialization in Extbase request handling. It requires a user-submitted payload to be signed with a corresponding HMAC-SHA1 using the sensitive TYPO3 encryptionKey as a secret. If the encryptionKey has been leaked, attackers could calculate the required HMAC-SHA1, allowing a malicious payload to be deserialized. This could happen if sensitive information was accidentally exposed in repositories, backup files, or other commonly known unprotected locations. For successful exploitation, at least one Extbase plugin must be rendered in the frontend, and the encryptionKey must have been leaked.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Typo3