CVE-2021-21359
Denial of Service in Page Error Handling
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 9.5.25, 10.4.14, 11.1.1 requesting invalid or non-existing resources via HTTP triggers the page error handler which again could retrieve content to be shown as error message from another page. This leads to a scenario in which the application is calling itself recursively - amplifying the impact of the initial attack until the limits of the web server are exceeded. This is fixed in versions 9.5.25, 10.4.14, 11.1.1.
TYPO3 es un sistema de gestión de contenidos web de código abierto basado en PHP. En TYPO3 versiones anteriores a la 9.5.25, 10.4.14, 11.1.1 la solicitud de recursos inválidos o inexistentes a través de HTTP desencadena el manejador de errores de la página que de nuevo podría recuperar el contenido que se muestra como mensaje de error de otra página. Esto lleva a un escenario en el que la aplicación se llama a sí misma de forma recursiva, amplificando el impacto del ataque inicial hasta que se superan los límites del servidor web. Esto se ha corregido en las versiones 9.5.25, 10.4.14 y 11.1.1
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-12-22 CVE Reserved
- 2021-03-23 CVE Published
- 2023-12-06 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-405: Asymmetric Resource Consumption (Amplification)
- CWE-674: Uncontrolled Recursion
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/TYPO3/TYPO3.CMS/security/advisories/GHSA-4p9g-qgx9-397p | Third Party Advisory | |
https://packagist.org/packages/typo3/cms-core | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://typo3.org/security/advisory/typo3-core-sa-2021-005 | 2021-03-26 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | >= 9.0.0 < 9.5.25 Search vendor "Typo3" for product "Typo3" and version " >= 9.0.0 < 9.5.25" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | >= 10.0.0 < 10.4.14 Search vendor "Typo3" for product "Typo3" and version " >= 10.0.0 < 10.4.14" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | >= 11.0.0 < 11.1.1 Search vendor "Typo3" for product "Typo3" and version " >= 11.0.0 < 11.1.1" | - |
Affected
|