CVE-2014-3941 – typo3/cms
Package
Manager: composer
Name: typo3/cms
Vulnerable Version: >=4.5.0 <4.5.34 || >=4.7.0 <4.7.19 || >=6.0.0 <6.0.14 || >=6.1.0 <6.1.9 || >=6.2.0 <6.2.3
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00276 pctl0.50686
Details
Typo3 Host Header Spoofing Vulnerability TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, 6.1.0 before 6.1.9, and 6.2.0 before 6.2.3 allows remote attackers to have unspecified impact via a crafted HTTP Host header, related to "Host Spoofing."
Metadata
Created: 2022-05-14T04:01:58Z
Modified: 2025-04-14T21:47:27Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-594h-cx6w-p4jf/GHSA-594h-cx6w-p4jf.json
CWE IDs: ["CWE-20"]
Alternative ID: GHSA-594h-cx6w-p4jf
Finding: F184
Auto approve: 1