CVE-2020-15098

In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, it has been discovered that an internal verification mechanism can be used to generate arbitrary checksums. This allows to inject arbitrary data having a valid cryptographic message authentication code (HMAC-SHA1) and can lead to various attack chains including potential privilege escalation, insecure deserialization & remote code execution. The overall severity of this vulnerability is high based on mentioned attack chains and the requirement of having a valid backend user session (authenticated). This has been patched in versions 9.5.20 and 10.4.6.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:04

Type Values Removed Values Added
References () https://github.com/TYPO3/TYPO3.CMS/commit/85d3e70dff35a99ef53f4b561114acfa9e5c47e1 - Broken Link () https://github.com/TYPO3/TYPO3.CMS/commit/85d3e70dff35a99ef53f4b561114acfa9e5c47e1 - Broken Link
References () https://github.com/TYPO3/TYPO3.CMS/security/advisories/GHSA-m5vr-3m74-jwxp - Third Party Advisory () https://github.com/TYPO3/TYPO3.CMS/security/advisories/GHSA-m5vr-3m74-jwxp - Third Party Advisory
References () https://typo3.org/security/advisory/typo3-core-sa-2016-013 - Vendor Advisory () https://typo3.org/security/advisory/typo3-core-sa-2016-013 - Vendor Advisory
References () https://typo3.org/security/advisory/typo3-core-sa-2020-008 - Vendor Advisory () https://typo3.org/security/advisory/typo3-core-sa-2020-008 - Vendor Advisory

Information

Published : 2020-07-29 17:15

Updated : 2024-11-21 05:04


NVD link : CVE-2020-15098

Mitre link : CVE-2020-15098

CVE.ORG link : CVE-2020-15098


JSON object : View

Products Affected

typo3

  • typo3
CWE
CWE-20

Improper Input Validation

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-325

Missing Cryptographic Step

CWE-502

Deserialization of Untrusted Data

CWE-327

Use of a Broken or Risky Cryptographic Algorithm