VDB
Sign up
HIGH

GHSA-jr8m-x4p7-p3v5

TYPO3 Remote Code Execution in extension "Site Crawler" (crawler)

Quick fix

GHSA-jr8m-x4p7-p3v5 — tomasnorre/crawler: upgrade to the fixed version with the command below.

composer require tomasnorre/crawler:^12.0.11

Details

The TYPO3 Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP's `unserialize()`. An attacker controlling a crawled endpoint can inject arbitrary serialized PHP objects, leading to Remote Code Execution on the TYPO3 server. Exploitation requires administrative privileges to configure a crawler-enabled page and trigger the crawl via a Scheduler task. This has been patched in versions 12.0.11 and 11.0.13.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/tomasnorre/crawler
Introduced in: 12.0.0Fixed in: 12.0.11
Fixcomposer require tomasnorre/crawler:^12.0.11
Packagist/tomasnorre/crawler
Introduced in: 0Fixed in: 11.0.13
Fixcomposer require tomasnorre/crawler:^11.0.13

References