SB2024100845 - Multiple vulnerabilities in TYPO3 CMS
Published: October 8, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Information disclosure (CVE-ID: CVE-2024-47780)
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. Backend users can see items in the backend page tree without having access if the mounts pointed to pages restricted for their user/group, or if no mounts were configured but the pages allowed access to "everybody".
2) Input validation error (CVE-ID: CVE-2024-34537)
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in the bookmark toolbar. A remote privileged user can trigger general error state and deny access to the interface.
Remediation
Install update from vendor's website.