Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cr4w-39ww-9jpm

Опубликовано: 20 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in the Varnishcache extension before 2.0.1 for TYPO3. The Edge Site Includes (ESI) content element renderer component does not include an access check. This allows an unauthenticated user to render various content elements, resulting in insecure direct object reference (IDOR), with the potential of exposing internal content elements.

An issue was discovered in the Varnishcache extension before 2.0.1 for TYPO3. The Edge Site Includes (ESI) content element renderer component does not include an access check. This allows an unauthenticated user to render various content elements, resulting in insecure direct object reference (IDOR), with the potential of exposing internal content elements.

EPSS

Процентиль: 45%
0.00226
Низкий

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 5.3
nvd
почти 4 года назад

An issue was discovered in the Varnishcache extension before 2.0.1 for TYPO3. The Edge Site Includes (ESI) content element renderer component does not include an access check. This allows an unauthenticated user to render various content elements, resulting in insecure direct object reference (IDOR), with the potential of exposing internal content elements.

EPSS

Процентиль: 45%
0.00226
Низкий

Дефекты

CWE-639