CVE-2010-3714: High severity Typo3 TYPO3 vulnerability
The jumpUrl (aka access tracking) implementation in tslib/class.tslibfe.php in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly compare certain hash values during access-control decisions, which allows remote attackers to read arbitrary files via unspecified vectors.
Other sources
The jumpUrl (aka access tracking) implementation in tslib/class.tslibfe.php in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly compare certain hash values during access-control decisions, which allows remote attackers to read arbitrary files via unspecified vectors.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3714?
CVE-2010-3714 has a medium severity rating due to its potential to allow unauthorized access to sensitive files.
How do I fix CVE-2010-3714?
To fix CVE-2010-3714, upgrade TYPO3 to version 4.2.15, 4.3.7, or 4.4.4 or later.
Which TYPO3 versions are affected by CVE-2010-3714?
TYPO3 versions 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 are affected by CVE-2010-3714.
Can CVE-2010-3714 lead to data breaches?
Yes, CVE-2010-3714 could potentially allow remote attackers to read arbitrary files, leading to data breaches.
Is there a workaround for CVE-2010-3714 if I can't upgrade?
There are no effective workarounds for CVE-2010-3714, so upgrading to a secure version is strongly recommended.