QID 997234

Date Published: 2024-02-15

QID 997234: PHP (Composer) Security Update for typo3/cms-core (GHSA-w6x2-jg8h-p6mp)

Configurable storages using the local driver of the File Abstraction Layer (FAL) could be configured to access directories outside of the root directory of the corresponding project. The system setting in BE/lockRootPath was not evaluated by the file abstraction layer component. An administrator-level backend user account is required to exploit this vulnerability.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 4.9 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-w6x2-jg8h-p6mp for updates and patch information.
    Vendor References

    CVEs related to QID 997234

    Software Advisories
    Advisory ID Software Component Link
    GHSA-w6x2-jg8h-p6mp typo3/cms-core URL Logo github.com/advisories/GHSA-w6x2-jg8h-p6mp