Skip to content

Insecure Deserialization in Backend User Settings

High
ohader published GHSA-2wj9-434x-9hvp May 12, 2020

Package

composer typo3/cms-core (Composer)

Affected versions

>=9.0.0 <=9.5.16, >=10.0.0 <=10.4.1

Patched versions

9.5.17, 10.4.2

Description

Meta

  • CVSS v3.1: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
  • CWE-502

Problem

It has been discovered that backend user settings (in $BE_USER->uc) are vulnerable to insecure deserialization. In combination with vulnerabilities of 3rd party components this can lead to remote code execution. A valid backend user account is needed to exploit this vulnerability.

Solution

Update to TYPO3 versions 9.5.17 or 10.4.2 that fix the problem described.

Credits

Thanks to TYPO3 security team member Oliver Hader who reported and fixed the issue.

References

Severity

High

CVE ID

CVE-2020-11067

Weaknesses

No CWEs

Credits