TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.25, 10.4.14, 11.1.1 requesting invalid or non-existing resources via HTTP triggers the page error handler which again could retrieve content to be shown as error message from another page. This leads to a scenario in which the application is calling itself recursively - amplifying the impact of the initial attack until the limits of the web server are exceeded. This is fixed in versions 9.5.25, 10.4.14, 11.1.1.
The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary’s influence is “asymmetric.”
Name | Vendor | Start Version | End Version |
---|---|---|---|
Typo3 | Typo3 | 9.0.0 (including) | 9.5.25 (excluding) |
Typo3 | Typo3 | 10.0.0 (including) | 10.4.14 (excluding) |
Typo3 | Typo3 | 11.0.0 (including) | 11.1.1 (excluding) |