HIGH
TYPO3 8.x through 8.7.26 and 9.x through 9.5.7 allows Deserialization of Untrusted Data
Published Jul 9, 2019
8.8
HIGHCVSS 3.1
EPSS 1.55%
Description
TYPO3 8.x through 8.7.26 and 9.x through 9.5.7 allows Deserialization of Untrusted Data.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- http://github.com/TYPO3/typo3/commit/647aa7afa582983cddc547fa106d31e2b1ef34fe
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-3124 Advisory
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2019-12747.yaml
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/CVE-2019-12747.yaml
- https://github.com/advisories/GHSA-86hp-xrhj-fhpq Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-12747
- https://typo3.org/cms/release-news/typo3-8-release-notes
- https://typo3.org/security/advisory/typo3-core-sa-2019-020 x_refsource_CONFIRMVendor Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 9, 2019
Updated Aug 4, 2024
Reserved Jun 6, 2019
Link CVE-2019-12747
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-3124 GHSA-86HP-XRHJ-FHPQ Assigner mitre
Published Jul 9, 2019
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2022-3124