VDB
Sign up
HIGH8.8

GHSA-2wj9-434x-9hvp

Insecure Deserialization in Backend User Settings in TYPO3 CMS

Quick fix

GHSA-2wj9-434x-9hvp — typo3/cms-core: upgrade to the fixed version with the command below.

composer require typo3/cms-core:^9.5.17

Details

It has been discovered that backend user settings (in $BE_USER->uc) are vulnerable to insecure deserialization. In combination with vulnerabilities of 3rd party components this can lead to remote code execution. A valid backend user account is needed to exploit this vulnerability.

Update to TYPO3 versions 9.5.17 or 10.4.2 that fix the problem described.

### References * https://typo3.org/security/advisory/typo3-core-sa-2020-005

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/typo3/cms-core
Introduced in: 9.0.0Fixed in: 9.5.17
Fixcomposer require typo3/cms-core:^9.5.17
Packagist/typo3/cms-core
Introduced in: 10.0.0Fixed in: 10.4.2
Fixcomposer require typo3/cms-core:^10.4.2
Packagist/typo3/cms
Introduced in: 10.0.0Fixed in: 10.4.2
Fixcomposer require typo3/cms:^10.4.2
Packagist/typo3/cms
Introduced in: 9.0.0Fixed in: 9.5.17
Fixcomposer require typo3/cms:^9.5.17

References