Security Advisories (RSS Feed)

LevelInfoBetroffene VersionenLösung
Low
October 8, 2024
TYPO3-CORE-SA-2024-012: Information Disclosure in TYPO3 Page Tree

It has been discovered that TYPO3 CMS is susceptible to information disclosure.
10.0.0-10.4.45
11.0.0-11.5.39
12.0.0-12.4.20
13.0.0-13.3.0
Update to TYPO3 versions 10.4.46 ELTS
11.5.40 LTS
12.4.21 LTS
13.3.1 that fix the problem described.
Low
October 8, 2024
TYPO3-CORE-SA-2024-011: Denial of Service in TYPO3 Bookmark Toolbar

It has been discovered that TYPO3 CMS is susceptible to denial of service.
10.0.0-10.4.45
11.0.0-11.5.39
12.0.0-12.4.20
13.0.0-13.3.0
Update to TYPO3 versions 10.4.46 ELTS
11.5.40 LTS
12.4.21 LTS
13.3.1 that fix the problem described.
Medium
September 17, 2024
TYPO3-EXT-SA-2024-007: Insecure Direct Object Reference in extension "powermail" (powermail)

It has been discovered that the extension "powermail" (powermail) is susceptible to Insecure Direct Object Reference.
7.5.0 and below
8.0.0 - 8.5.0
9.0.0 - 10.9.0
12.0.0 - 12.4.0
Updated versions 7.5.1
8.5.1
10.9.1 and 12.4.1 are  available from the TYPO3 extension manager
packagist and at  https://extensions.typo3.org/extension/download/powermail/7.5.1/ziphttps://extensions.typo3.org/extension/download/powermail/8.5.1/ziphttps://extensions.typo3.org/extension/download/powermail/10.9.1/ziphttps://extensions.typo3.org/extension/download/powermail/12.4.1/zipUsers of the extension are advised to update the extension as soon as possible.
Medium
August 27, 2024
TYPO3-EXT-SA-2024-006: Multiple vulnerabilities in "powermail" (powermail)

It has been discovered that the extension "powermail" (powermail) is susceptible to Insecure Direct Object Reference and Broken Access Control.
7.4.3 and below
8.0.0 - 8.4.2
9.0.0 - 10.8.2
12.0.0 - 12.3.5
Updated versions 7.5.0
8.5.0
10.9.0 and 12.4.0 are  available from the TYPO3 extension manager
packagist and at  https://extensions.typo3.org/extension/download/powermail/7.5.0/ziphttps://extensions.typo3.org/extension/download/powermail/8.5.0/ziphttps://extensions.typo3.org/extension/download/powermail/10.9.0/zip https://extensions.typo3.org/extension/download/powermail/12.4.0/zipUsers of the extension are advised to update the extension as soon as possible.
High
June 18, 2024
TYPO3-EXT-SA-2024-005: Multiple vulnerabilities in "Aimeos shop and e-commerce framework" (aimeos)

It has been discovered that the extension "Aimeos shop and e-commerce framework" (aimeos) is susceptible to Remote Code Execution and Insecure Direct Object Reference.
22.10.9 and below
23.0.0 - 23.10.6
24.0.0 - 24.4.1
Updated versions 22.10.10
23.10.7 and 24.4.2 are available from the TYPO3 extension manager
packagist and athttps://extensions.typo3.org/extension/download/aimeos/22.10.10/ziphttps://extensions.typo3.org/extension/download/aimeos/23.10.7/ziphttps://extensions.typo3.org/extension/download/aimeos/24.4.2/zipUsers of the extension are advised to update the extension as soon as possible.
weitere links zur Sicherheit von Typo3: Alle Security Advisories (RSS Feed) Einträge zeigen |TYPO3 CMS |TYPO3 Extensions |Public Service Announcements |
typo3-coret3tsbase url hostname scheduler-status php-version db-version mask news t3adminer fontawesome_provider ke_search powermail femanager simple_log404 typo3_console container form_element_linked_checkbox gridelements mfa_email numbered_pagination rte_ckeditor_image secure_downloads solr solradmin translate_locallang displaydownloads extension_builder hcaptcha ke_search_premium phpmyadmin replacer solr_file_indexer sysfilemetadata_addfields t3gurom t3massnahmen tsoffer tt_address typo3db_legacy vhs
SecurityInfos von Typo3.org:
p2 | p7 | p10
p1 | p2 | p3 | p5 | p8 | p10
p6 | p8 | p9 | p10
10.4.3711.2.12https://www.timespin.de | FE | TYPO3-BE | Wikilive.timespin.deOK (0)7.4.3-4ubuntu2.285.5.5-10.3.39-MariaDB-0ubuntu0.20.04.26.6.18.5.2
10.4.4711.2.12https://awothueringen.de | FE | TYPO3-BE | Wikikm30718.keymachine.deOK (2)7.4.335.5.5-10.3.39-MariaDB-0ubuntu0.20.04.26.2.28.6.010.0.04.1.16.0.12.1.1
10.4.4711.2.14https://www.kindersprachbruecke.de | FE | TYPO3-BE | Wikis1230OK (3)7.4.33.85.7.35-386.4.58.5.24.0.38.5.16.7.710.4.31.4.0
10.4.4711.2.12https://www.th-ern.net | FE | TYPO3-BE | Wikis1134OK (3)7.4.33.85.7.35-385.1.18.3.04.6.68.5.16.7.710.4.35.1.2
11.5.4011.2.16https://www.gurom.de | FE | TYPO3-BE | Wikiwww521.your-server.deOK (4)7.4.335.5.5-10.11.6-MariaDB-hetzner18.3.1112.0.11.0.37.4.01.1.2.TS-Patched11.0.1311.2.011.2.01.2.0
11.5.4111.2.12https://www.uniwind.org | FE | TYPO3-BE | Wikis1124OK (2)8.1.315.7.35-388.3.1111.4.212.0.11.0.310.9.18.1.12.3.6
12.4.2112.3.1https://sgs-institut-fresenius.de | FE | TYPO3-BE | WikijonesOK (12)8.2.2210.3.39-MariaDB-0ubuntu0.20.04.28.3.1111.4.212.0.11.0.31.2.0_TS-Patched4.0.01.0.512.0.2_TS-Patched12.0.52.0.13.1.0
12.4.2112.2.7https://sgs-proderm.de | FE | TYPO3-BE | WikijonesOK (9)8.2.2210.3.39-MariaDB-0ubuntu0.20.04.28.3.1111.4.212.0.11.0.31.2.2_TS-Patched4.0.01.0.512.0.2_TS-Patched12.0.52.0.13.1.02.2.03.0.07.0.6
12.4.2112.2.7https://www.kv-thueringen.de | FE | TYPO3-BE | Wikiwww507.your-server.deOK (8)8.2.2710.11.6-MariaDB-hetzner18.3.1111.4.212.0.11.0.35.5.28.2.02.0.05.0.412.2.8
12.4.2112.2.2https://www.varys.de | FE | TYPO3-BE | Wikiwww527.your-server.deOK (5)8.2.2710.5.26-MariaDB-0+deb11u28.3.1111.4.212.0.11.0.35.5.212.4.28.2.02.3.62.0.06.0.412.2.2