VDB
Sign up
MEDIUM

GHSA-594h-cx6w-p4jf

Typo3 Host Header Spoofing Vulnerability

Quick fix

GHSA-594h-cx6w-p4jf — typo3/cms: upgrade to the fixed version with the command below.

composer require typo3/cms:^4.5.34

Details

TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, 6.1.0 before 6.1.9, and 6.2.0 before 6.2.3 allows remote attackers to have unspecified impact via a crafted HTTP Host header, related to "Host Spoofing."

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/typo3/cms
Introduced in: 4.5.0Fixed in: 4.5.34
Fixcomposer require typo3/cms:^4.5.34
Packagist/typo3/cms
Introduced in: 4.7.0Fixed in: 4.7.19
Fixcomposer require typo3/cms:^4.7.19
Packagist/typo3/cms
Introduced in: 6.0.0Fixed in: 6.0.14
Fixcomposer require typo3/cms:^6.0.14
Packagist/typo3/cms
Introduced in: 6.1.0Fixed in: 6.1.9
Fixcomposer require typo3/cms:^6.1.9
Packagist/typo3/cms
Introduced in: 6.2.0Fixed in: 6.2.3
Fixcomposer require typo3/cms:^6.2.3

References