Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7jfm-px59-99w8

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

Typo3 Extbase Framework Unsafe Deserialization

The Extbase Framework in TYPO3 4.6.x through 4.6.6, 4.7, and 6.0 unserializes untrusted data, which allows remote attackers to unserialize arbitrary objects and possibly execute arbitrary code via vectors related to "a missing signature (HMAC) for a request argument."

Пакеты

Наименование

typo3/cms

composer
Затронутые версииВерсия исправления

>= 4.6, <= 4.6.6

4.6.7

Наименование

typo3/cms

composer
Затронутые версииВерсия исправления

>= 4.4.0, < 4.4.14

4.4.14

Наименование

typo3/cms

composer
Затронутые версииВерсия исправления

>= 4.5.0, < 4.5.14

4.5.14

EPSS

Процентиль: 76%
0.0094
Низкий

Дефекты

CWE-502

Связанные уязвимости

ubuntu
больше 13 лет назад

The Extbase Framework in TYPO3 4.6.x through 4.6.6, 4.7, and 6.0 unserializes untrusted data, which allows remote attackers to unserialize arbitrary objects and possibly execute arbitrary code via vectors related to "a missing signature (HMAC) for a request argument." To our knowledge it is neither possible to inject code through this vulnerability, nor are there exploitable objects within the TYPO3 Core. However, there might be exploitable objects within third party extensions.

nvd
больше 13 лет назад

The Extbase Framework in TYPO3 4.6.x through 4.6.6, 4.7, and 6.0 unserializes untrusted data, which allows remote attackers to unserialize arbitrary objects and possibly execute arbitrary code via vectors related to "a missing signature (HMAC) for a request argument."

debian
больше 13 лет назад

The Extbase Framework in TYPO3 4.6.x through 4.6.6, 4.7, and 6.0 unser ...

EPSS

Процентиль: 76%
0.0094
Низкий

Дефекты

CWE-502