CVE-2014-9509
Summary
| CVE | CVE-2014-9509 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-01-04 21:59:07 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, when config.prefixLocalAnchors is set to all or cached, allows remote attackers to have an unspecified impact (possibly resource consumption) via a "Cache Poisoning" attack using a URL with arbitrary arguments, which triggers a reload of the page. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Typo3 | Typo3 | 4.5.0 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.1 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.10 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.11 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.12 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.13 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.14 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.15 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.16 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.17 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.18 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.19 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.2 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.20 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.21 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.22 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.23 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.24 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.25 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.26 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.27 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.28 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.29 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.3 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.30 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.31 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.32 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.33 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.34 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.35 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.36 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.37 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.38 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.4 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.5 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.6 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.7 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.8 | All | All | All |
| Application | Typo3 | Typo3 | 4.5.9 | All | All | All |
| Application | Typo3 | Typo3 | 4.6.0 | All | All | All |
| Application | Typo3 | Typo3 | 4.6.1 | All | All | All |
| Application | Typo3 | Typo3 | 4.6.10 | All | All | All |
| Application | Typo3 | Typo3 | 4.6.11 | All | All | All |
| Application | Typo3 | Typo3 | 4.6.12 | All | All | All |
| Application | Typo3 | Typo3 | 4.6.13 | All | All | All |
| Application | Typo3 | Typo3 | 4.6.14 | All | All | All |
| Application | Typo3 | Typo3 | 4.6.15 | All | All | All |
| Application | Typo3 | Typo3 | 4.6.16 | All | All | All |
| Application | Typo3 | Typo3 | 4.6.17 | All | All | All |
| Application | Typo3 | Typo3 | 4.6.18 | All | All | All |
| Application | Typo3 | Typo3 | 4.6.2 | All | All | All |
| Application | Typo3 | Typo3 | 4.6.3 | All | All | All |
| Application | Typo3 | Typo3 | 4.6.4 | All | All | All |
| Application | Typo3 | Typo3 | 4.6.5 | All | All | All |
| Application | Typo3 | Typo3 | 4.6.6 | All | All | All |
| Application | Typo3 | Typo3 | 4.6.7 | All | All | All |
| Application | Typo3 | Typo3 | 4.6.8 | All | All | All |
| Application | Typo3 | Typo3 | 4.6.9 | All | All | All |
| Application | Typo3 | Typo3 | 4.7.0 | All | All | All |
| Application | Typo3 | Typo3 | 4.7.1 | All | All | All |
| Application | Typo3 | Typo3 | 4.7.10 | All | All | All |
| Application | Typo3 | Typo3 | 4.7.11 | All | All | All |
| Application | Typo3 | Typo3 | 4.7.12 | All | All | All |
| Application | Typo3 | Typo3 | 4.7.13 | All | All | All |
| Application | Typo3 | Typo3 | 4.7.14 | All | All | All |
| Application | Typo3 | Typo3 | 4.7.15 | All | All | All |
| Application | Typo3 | Typo3 | 4.7.16 | All | All | All |
| Application | Typo3 | Typo3 | 4.7.17 | All | All | All |
| Application | Typo3 | Typo3 | 4.7.18 | All | All | All |
| Application | Typo3 | Typo3 | 4.7.19 | All | All | All |
| Application | Typo3 | Typo3 | 4.7.2 | All | All | All |
| Application | Typo3 | Typo3 | 4.7.20 | All | All | All |
| Application | Typo3 | Typo3 | 4.7.3 | All | All | All |
| Application | Typo3 | Typo3 | 4.7.4 | All | All | All |
| Application | Typo3 | Typo3 | 4.7.5 | All | All | All |
| Application | Typo3 | Typo3 | 4.7.6 | All | All | All |
| Application | Typo3 | Typo3 | 4.7.7 | All | All | All |
| Application | Typo3 | Typo3 | 4.7.8 | All | All | All |
| Application | Typo3 | Typo3 | 4.7.9 | All | All | All |
| Application | Typo3 | Typo3 | 6.0 | All | All | All |
| Application | Typo3 | Typo3 | 6.0.1 | All | All | All |
| Application | Typo3 | Typo3 | 6.0.10 | All | All | All |
| Application | Typo3 | Typo3 | 6.0.11 | All | All | All |
| Application | Typo3 | Typo3 | 6.0.12 | All | All | All |
| Application | Typo3 | Typo3 | 6.0.13 | All | All | All |
| Application | Typo3 | Typo3 | 6.0.14 | All | All | All |
| Application | Typo3 | Typo3 | 6.0.2 | All | All | All |
| Application | Typo3 | Typo3 | 6.0.3 | All | All | All |
| Application | Typo3 | Typo3 | 6.0.4 | All | All | All |
| Application | Typo3 | Typo3 | 6.0.5 | All | All | All |
| Application | Typo3 | Typo3 | 6.0.6 | All | All | All |
| Application | Typo3 | Typo3 | 6.0.7 | All | All | All |
| Application | Typo3 | Typo3 | 6.0.8 | All | All | All |
| Application | Typo3 | Typo3 | 6.0.9 | All | All | All |
| Application | Typo3 | Typo3 | 6.1 | All | All | All |
| Application | Typo3 | Typo3 | 6.1.1 | All | All | All |
| Application | Typo3 | Typo3 | 6.1.2 | All | All | All |
| Application | Typo3 | Typo3 | 6.1.3 | All | All | All |
| Application | Typo3 | Typo3 | 6.1.4 | All | All | All |
| Application | Typo3 | Typo3 | 6.1.5 | All | All | All |
| Application | Typo3 | Typo3 | 6.1.6 | All | All | All |
| Application | Typo3 | Typo3 | 6.1.7 | All | All | All |
| Application | Typo3 | Typo3 | 6.1.8 | All | All | All |
| Application | Typo3 | Typo3 | 6.1.9 | All | All | All |
| Application | Typo3 | Typo3 | 6.2 | All | All | All |
| Application | Typo3 | Typo3 | 6.2.0 | beta1 | All | All |
| Application | Typo3 | Typo3 | 6.2.0 | beta2 | All | All |
| Application | Typo3 | Typo3 | 6.2.0 | beta3 | All | All |
| Application | Typo3 | Typo3 | 6.2.1 | All | All | All |
| Application | Typo3 | Typo3 | 6.2.2 | All | All | All |
| Application | Typo3 | Typo3 | 6.2.3 | All | All | All |
| Application | Typo3 | Typo3 | 6.2.4 | All | All | All |
| Application | Typo3 | Typo3 | 6.2.5 | All | All | All |
| Application | Typo3 | Typo3 | 6.2.6 | All | All | All |
| Application | Typo3 | Typo3 | 6.2.7 | All | All | All |
| Application | Typo3 | Typo3 | 6.2.8 | All | All | All |
| Application | Typo3 | Typo3 | 7.0.0 | All | All | All |
| Application | Typo3 | Typo3 | 7.0.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Link spoofing and cache poisoning vulnerabilities in TYPO3 CMS - - TYPO3 - The Enterprise Open Source CMS | af854a3a-2127-422b-91ae-364da2661108 | typo3.org | Exploit, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 994901 PHP (Composer) Security Update for typo3/cms (GHSA-5479-gqqr-f9gj)