CVE Vulnerabilities

CVE-2010-3714

Published: Oct 25, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.1 HIGH
AV:N/AC:M/Au:N/C:C/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The jumpUrl (aka access tracking) implementation in tslib/class.tslib_fe.php in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly compare certain hash values during access-control decisions, which allows remote attackers to read arbitrary files via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
Typo3Typo34.2.0 (including)4.2.0 (including)
Typo3Typo34.2.1 (including)4.2.1 (including)
Typo3Typo34.2.2 (including)4.2.2 (including)
Typo3Typo34.2.3 (including)4.2.3 (including)
Typo3Typo34.2.4 (including)4.2.4 (including)
Typo3Typo34.2.5 (including)4.2.5 (including)
Typo3Typo34.2.6 (including)4.2.6 (including)
Typo3Typo34.2.7 (including)4.2.7 (including)
Typo3Typo34.2.8 (including)4.2.8 (including)
Typo3Typo34.2.9 (including)4.2.9 (including)
Typo3Typo34.2.10 (including)4.2.10 (including)
Typo3Typo34.2.11 (including)4.2.11 (including)
Typo3Typo34.2.12 (including)4.2.12 (including)
Typo3Typo34.2.13 (including)4.2.13 (including)
Typo3Typo34.2.14 (including)4.2.14 (including)
Typo3Typo34.3.0 (including)4.3.0 (including)
Typo3Typo34.3.1 (including)4.3.1 (including)
Typo3Typo34.3.2 (including)4.3.2 (including)
Typo3Typo34.3.3 (including)4.3.3 (including)
Typo3Typo34.3.4 (including)4.3.4 (including)
Typo3Typo34.3.5 (including)4.3.5 (including)
Typo3Typo34.3.6 (including)4.3.6 (including)
Typo3Typo34.4 (including)4.4 (including)
Typo3Typo34.4.1 (including)4.4.1 (including)
Typo3Typo34.4.2 (including)4.4.2 (including)
Typo3Typo34.4.3 (including)4.4.3 (including)
Typo3-srcUbuntudapper*
Typo3-srcUbuntuhardy*
Typo3-srcUbuntujaunty*
Typo3-srcUbuntukarmic*
Typo3-srcUbuntulucid*
Typo3-srcUbuntumaverick*
Typo3-srcUbuntunatty*
Typo3-srcUbuntuupstream*

References