CVE-2009-0815: Infoleak
The jumpUrl mechanism in class.tslibfe.php in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 leaks a hash secret (juHash) in an error message, which allows remote attackers to read arbitrary files by including the hash in a request.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/typo3/cmsto a version that resolves this vulnerability.Fixed in 4.2.6 - Upgrade
Upgrade
composer/typo3/cmsto a version that resolves this vulnerability.Fixed in 4.1.10 - Upgrade
Upgrade
composer/typo3/cmsto a version that resolves this vulnerability.Fixed in 4.0.12
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0815?
CVE-2009-0815 is considered a high severity vulnerability due to its potential to leak sensitive hash information.
How do I fix CVE-2009-0815?
To fix CVE-2009-0815, update TYPO3 to version 4.0.12 or later, 4.1.10 or later, 4.2.6 or later, or ensure you are not using affected versions below these.
What types of TYPO3 versions are affected by CVE-2009-0815?
CVE-2009-0815 affects TYPO3 versions from 3.3.x to 3.8.x and multiple versions of 4.x before their respective patch releases.
What can an attacker do with CVE-2009-0815?
An attacker can exploit CVE-2009-0815 to read arbitrary files on the server by manipulating the hash value in a request.
Is CVE-2009-0815 still relevant today?
Yes, CVE-2009-0815 remains relevant for organizations using outdated versions of TYPO3, as it poses a significant security risk.