CVE-2024-25121: Improper Access Control Persisting File Abstraction Layer Entities via Data Handler in TYPO3

Published Feb 13, 2024
·
Updated

Problem Entities of the File Abstraction Layer (FAL) could be persisted directly via DataHandler. This allowed attackers to reference files in the fallback storage directly and retrieve their file names and contents. The fallback storage ("zero-storage") is used as a backward compatibility layer for files located outside properly configured file storages and within the public web root directory. Exploiting this vulnerability requires a valid backend user account.

Solution Update to TYPO3 versions 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, 13.0.1 that fix the problem described.

ℹ️ Strong security defaults - Manual actions required

When persisting entities of the File Abstraction Layer directly via DataHandler, sysfile entities are now denied by default, and sysfilereference & sysfilemetadata entities are not permitted to reference files in the fallback storage anymore.

When importing data from secure origins, this must be explicitly enabled in the corresponding DataHandler instance by using $dataHandler->isImporting = true;.

Credits Thanks to TYPO3 core & security team member Oliver Hader who reported and fixed the issue.

References TYPO3-CORE-SA-2024-006

Other sources

TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions of TYPO3 entities of the File Abstraction Layer (FAL) could be persisted directly via DataHandler. This allowed attackers to reference files in the fallback storage directly and retrieve their file names and contents. The fallback storage ("zero-storage") is used as a backward compatibility layer for files located outside properly configured file storages and within the public web root directory. Exploiting this vulnerability requires a valid backend user account. Users are advised to update to TYPO3 version 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, or 13.0.1 which fix the problem described. When persisting entities of the File Abstraction Layer directly via DataHandler, sysfile entities are now denied by default, and sysfilereference & sysfilemetadata entities are not permitted to reference files in the fallback storage anymore. When importing data from secure origins, this must be explicitly enabled in the corresponding DataHandler instance by using $dataHandler->isImporting = true;.

NVD

Affected Software

12 affected componentsFixes available
composer/typo3/cms-core=13.0.0
13.0.1
composer/typo3/cms-core>=12.0.0<=12.4.10
12.4.11
composer/typo3/cms-core>=11.0.0<=11.5.34
11.5.35
composer/typo3/cms-core>=10.0.0<=10.4.42
10.4.43
composer/typo3/cms-core>=9.0.0<=9.5.45
9.5.46
composer/typo3/cms-core>=8.0.0<=8.7.56
8.7.57
Typo3 TYPO3>=8.0.0<8.7.57
Typo3 TYPO3>=9.0.0<9.5.46
Typo3 TYPO3>=10.0.0<10.4.43
Typo3 TYPO3>=11.0.0<11.5.35
Typo3 TYPO3>=12.0.0<12.4.11
Typo3 TYPO3=13.0.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade composer/typo3/cms-core to a version that resolves this vulnerability.

    Fixed in 13.0.1
  2. Upgrade

    Upgrade composer/typo3/cms-core to a version that resolves this vulnerability.

    Fixed in 12.4.11
  3. Upgrade

    Upgrade composer/typo3/cms-core to a version that resolves this vulnerability.

    Fixed in 11.5.35
  4. Upgrade

    Upgrade composer/typo3/cms-core to a version that resolves this vulnerability.

    Fixed in 10.4.43
  5. Upgrade

    Upgrade composer/typo3/cms-core to a version that resolves this vulnerability.

    Fixed in 9.5.46
  6. Upgrade

    Upgrade composer/typo3/cms-core to a version that resolves this vulnerability.

    Fixed in 8.7.57
  7. Upgrade

    Upgrade TYPO3 to a version that resolves this vulnerability.

    Fixed in 8.7.57
  8. Upgrade

    Upgrade TYPO3 to a version that resolves this vulnerability.

    Fixed in 9.5.46
  9. Upgrade

    Upgrade TYPO3 to a version that resolves this vulnerability.

    Fixed in 10.4.43
  10. Upgrade

    Upgrade TYPO3 to a version that resolves this vulnerability.

    Fixed in 11.5.35
  11. Upgrade

    Upgrade TYPO3 to a version that resolves this vulnerability.

    Fixed in 12.4.11
  12. Upgrade

    Upgrade TYPO3 to a version that resolves this vulnerability.

    Fixed in 13.0.1
  13. Configuration

    When importing data from secure origins, explicitly enable importing in the corresponding DataHandler instance by setting `$dataHandler->isImporting = true;`.

    TYPO3 DataHandler isImporting = true
  14. Configuration

    After upgrading, ensure the default FAL access controls are enforced: `sys_file` entities are denied by default, and `sys_file_reference` & `sys_file_metadata` entities must not reference files in the fallback storage ("zero-storage").

    TYPO3 File Abstraction Layer (FAL) via DataHandler FAL entity persistence rules for DataHandler = deny sys_file; restrict sys_file_reference & sys_file_metadata fallback storage

Event History

Feb 13, 2024
Advisory Published
via GitHub·05:29 PM
CVE Published
via MITRE·10:14 PM
Data Sourced
via MITRE·10:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
Affected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-25121?

CVE-2024-25121 has been classified with a significant severity as it can lead to unauthorized access to sensitive file data.

2

How do I fix CVE-2024-25121?

To mitigate CVE-2024-25121, update TYPO3 to versions 13.0.1, 12.4.11, 11.5.35, 10.4.43, 9.5.46, or 8.7.57.

3

What types of software are affected by CVE-2024-25121?

CVE-2024-25121 affects multiple TYPO3 CMS versions, specifically those from 8.0.0 to 13.0.0.

4

What vulnerability mechanism is involved in CVE-2024-25121?

CVE-2024-25121 exploits a flaw in the File Abstraction Layer, allowing attackers to reference and access fallback storage files.

5

Can I track updates or references for CVE-2024-25121?

Yes, updates and references for CVE-2024-25121 can be found in TYPO3 security advisories and GitHub repositories.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203