HIGH8.8
GHSA-4r76-xr68-w7m7
TYPO3 may allow editors to change, create, or delete metadata of files not within their file mounts
Quick fix
GHSA-4r76-xr68-w7m7 — typo3/cms: upgrade to the fixed version with the command below.
composer require typo3/cms:^6.2.14Details
It has been discovered, that editors with access to file meta data table could change, create or delete metadata of files which are not within their file mounts.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/TYPO3/typo3/commit/0decbf83c531cab77497429eb2edecf9a1038b25[WEB]
- https://github.com/TYPO3/typo3/commit/bff9fa5945801d1d2c641ddc8eb86c6647549d80[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/2015-07-01-1.yaml[WEB]
- https://github.com/TYPO3/typo3[PACKAGE]
- https://typo3.org/security/advisory/typo3-core-sa-2015-002[WEB]
- https://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2015-002[WEB]