CVE-2024-25120: Improper Access Control of Resources Referenced by t3:// URI Scheme in TYPO3
Problem The TYPO3-specific t3:// URI scheme could be used to access resources outside of the users' permission scope. This encompassed files, folders, pages, and records (although only if a valid link-handling configuration was provided). Exploiting this vulnerability requires a valid backend user account.
Solution Update to TYPO3 versions 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, 13.0.1 that fix the problem described.
Credits Thanks to Richie Lee who reported this issue and to TYPO3 core & security team member Benjamin Franzke who fixed the issue.
References TYPO3-CORE-SA-2024-005
Other sources
TYPO3 is an open source PHP based web content management system released under the GNU GPL. The TYPO3-specific t3:// URI scheme could be used to access resources outside of the users' permission scope. This encompassed files, folders, pages, and records (although only if a valid link-handling configuration was provided). Exploiting this vulnerability requires a valid backend user account. Users are advised to update to TYPO3 versions 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, 13.0.1 that fix the problem described. There are no known workarounds for this issue.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 13.0.1 - Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 12.4.11 - Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 11.5.35 - Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 10.4.43 - Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 9.5.46 - Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 8.7.57 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch TYPO3-CORE-SA-2024-005 - Upgrade
Upgrade
TYPO3to a version that resolves this vulnerability.Fixed in 8.7.57 ELTS - Upgrade
Upgrade
TYPO3to a version that resolves this vulnerability.Fixed in 9.5.46 ELTS - Upgrade
Upgrade
TYPO3to a version that resolves this vulnerability.Fixed in 10.4.43 ELTS - Upgrade
Upgrade
TYPO3to a version that resolves this vulnerability.Fixed in 11.5.35 LTS - Upgrade
Upgrade
TYPO3to a version that resolves this vulnerability.Fixed in 12.4.11 LTS - Upgrade
Upgrade
TYPO3to a version that resolves this vulnerability.Fixed in 13.0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25120?
CVE-2024-25120 has a medium severity rating due to the potential for unauthorized access to resources.
How do I fix CVE-2024-25120?
To fix CVE-2024-25120, update to TYPO3 versions 13.0.1, 12.4.11, 11.5.35, 10.4.43, 9.5.46, or 8.7.57.
What impact does CVE-2024-25120 have on TYPO3 installations?
CVE-2024-25120 allows access to files, folders, pages, and records beyond a user's permission scope, posing a security risk.
Which TYPO3 versions are affected by CVE-2024-25120?
CVE-2024-25120 affects TYPO3 versions 8.0.0 to 13.0.0.
Is CVE-2024-25120 related to a specific TYPO3 functionality?
CVE-2024-25120 is related to the TYPO3-specific 't3://' URI scheme that can be exploited to access restricted resources.