Uncontrolled Recursion Affecting typo3/cms package, versions >=9.0.0, <10.4.33>=11.0.0, <11.5.20


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.09% (40th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-TYPO3CMS-3168673
  • published14 Dec 2022
  • disclosed13 Dec 2022
  • creditUnknown

Introduced: 13 Dec 2022

CVE-2022-23500  (opens in a new tab)
CWE-674  (opens in a new tab)

How to fix?

Upgrade typo3/cms to version 10.4.33, 11.5.20 or higher.

Overview

typo3/cms is a free open source Content Management Framework.

Affected versions of this package are vulnerable to Uncontrolled Recursion such that requesting invalid or non-existing resources via HTTP triggers the page error handler, which again could retrieve content to be shown as an error message from another page. This leads to a scenario in which the application is calling itself recursively - amplifying the impact of the initial attack until the limits of the web server are exceeded.

This vulnerability is very similar, but not identical, to the one described in TYPO3-CORE-SA-2021-005 (CVE-2021-21359).

CVSS Scores

version 3.1