U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2023-24814

Change History

Initial Analysis by NIST 2/16/2023 11:38:32 AM

Action Type Old Value New Value
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* versions from (including) 8.7.0 up to (excluding) 9.7.51
     *cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* versions from (including) 9.0.0 up to (excluding) 9.5.40
     *cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* versions from (including) 10.0.0 up to (excluding) 10.4.36
     *cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* versions from (including) 11.0.0 up to (excluding) 11.5.23
     *cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* versions from (including) 12.0.0 up to (excluding) 12.2.0
Added CVSS V3.1

								
							
							
						
NIST AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Added CWE

								
							
							
						
NIST CWE-79
Changed Reference Type
https://docs.typo3.org/m/typo3/reference-typoscript/main/en-us/Setup/Config/Index.html#absrefprefix No Types Assigned
https://docs.typo3.org/m/typo3/reference-typoscript/main/en-us/Setup/Config/Index.html#absrefprefix Not Applicable
Changed Reference Type
https://github.com/TYPO3/typo3/blob/v11.5.22/typo3/sysext/core/Classes/Utility/GeneralUtility.php#L2481-L2484 No Types Assigned
https://github.com/TYPO3/typo3/blob/v11.5.22/typo3/sysext/core/Classes/Utility/GeneralUtility.php#L2481-L2484 Product
Changed Reference Type
https://github.com/TYPO3/typo3/blob/v11.5.22/typo3/sysext/frontend/Classes/Controller/TypoScriptFrontendController.php#L2547-L2549 No Types Assigned
https://github.com/TYPO3/typo3/blob/v11.5.22/typo3/sysext/frontend/Classes/Controller/TypoScriptFrontendController.php#L2547-L2549 Product
Changed Reference Type
https://github.com/TYPO3/typo3/commit/0005a6fd86ab97eff8bf2e3a5828bf0e7cb6263a No Types Assigned
https://github.com/TYPO3/typo3/commit/0005a6fd86ab97eff8bf2e3a5828bf0e7cb6263a Patch
Changed Reference Type
https://github.com/TYPO3/typo3/security/advisories/GHSA-r4f8-f93x-5qh3 No Types Assigned
https://github.com/TYPO3/typo3/security/advisories/GHSA-r4f8-f93x-5qh3 Exploit, Mitigation, Vendor Advisory
Changed Reference Type
https://typo3.org/security/advisory/typo3-core-sa-2023-001 No Types Assigned
https://typo3.org/security/advisory/typo3-core-sa-2023-001 Exploit, Mitigation, Vendor Advisory
Changed Reference Type
https://typo3.org/security/advisory/typo3-psa-2023-001 No Types Assigned
https://typo3.org/security/advisory/typo3-psa-2023-001 Vendor Advisory