logo

CVE-2014-3941 typo3/cms

Package

Manager: composer
Name: typo3/cms
Vulnerable Version: >=4.5.0 <4.5.34 || >=4.7.0 <4.7.19 || >=6.0.0 <6.0.14 || >=6.1.0 <6.1.9 || >=6.2.0 <6.2.3

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00276 pctl0.50686

Details

Typo3 Host Header Spoofing Vulnerability TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, 6.1.0 before 6.1.9, and 6.2.0 before 6.2.3 allows remote attackers to have unspecified impact via a crafted HTTP Host header, related to "Host Spoofing."

Metadata

Created: 2022-05-14T04:01:58Z
Modified: 2025-04-14T21:47:27Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-594h-cx6w-p4jf/GHSA-594h-cx6w-p4jf.json
CWE IDs: ["CWE-20"]
Alternative ID: GHSA-594h-cx6w-p4jf
Finding: F184
Auto approve: 1