CVE-2024-55892
Last modified
CVE-2024-55892 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. TYPO3 is a free and open source Content Management Framework. Applications that use `TYPO3\CMS\Core\Http\Uri` to parse externally provided URLs (e.g., via a query parameter) and validate the host of the parsed URL may be vulnerable to open redirect or SSRF attacks if the URL is used after passing the validation checks. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
TYPO3 is a free and open source Content Management Framework. Applications that use `TYPO3\CMS\Core\Http\Uri` to parse externally provided URLs (e.g., via a query parameter) and validate the host of the parsed URL may be vulnerable to open redirect or SSRF attacks if the URL is used after passing the validation checks. Users are advised to update to TYPO3 versions 9.5.49 ELTS, 10.4.48 ELTS, 11.5.42 LTS, 12.4.25 LTS, 13.4.3 which fix the problem described. There are no known workarounds for this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Typo3 | Typo3 | >= 9.0.0, < 9.5.49 |
| Typo3 | Typo3 | >= 10.0.0, < 10.4.48 |
| Typo3 | Typo3 | >= 11.0.0, < 11.5.42 |
| Typo3 | Typo3 | >= 12.0.0, < 12.4.25 |
| Typo3 | Typo3 | >= 13.0.0, < 13.4.3 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-55892?
How severe is CVE-2024-55892?
How do I fix CVE-2024-55892?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-55887Ucum-java is a FHIR Java library providing UCUM Services. In…8.6
- CVE-2024-55888Hush Line is an open-source whistleblower management system.…7.1
- CVE-2024-55889phpMyFAQ is an open source FAQ web application. Prior to ver…7.2
- CVE-2024-5589A vulnerability was found in Netentsec NS-ASG Application Se…9.8
- CVE-2024-55890D-Tale is a visualizer for pandas data structures. Prior to …6.9
- CVE-2024-55891TYPO3 is a free and open source Content Management Framework…5.3
- CVE-2024-55893TYPO3 is a free and open source Content Management Framework…4.3
- CVE-2024-55894TYPO3 is a free and open source Content Management Framework…5.4
- CVE-2024-55895IBM InfoSphere Information Server 11.7 could allow a remote …5.3
- CVE-2024-55896IBM PowerHA SystemMirror for i 7.4 and 7.5 contains improper…5.4
- CVE-2024-55897IBM PowerHA SystemMirror for i 7.4 and 7.5 does not set th…4.3
- CVE-2024-55898IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user with the cap…8.5
Are you affected by CVE-2024-55892?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
