CVE-2022-24980
Dashboard / Vulnerabilities / CVE-2022-24980
Summary:
Details: An issue was discovered in the Kitodo.Presentation (aka dif) extension before 2.3.2, 3.x before 3.2.3, and 3.3.x before 3.3.4 for TYPO3. A missing access check in an eID script allows an unauthenticated user to submit arbitrary URLs to this component. This results in SSRF, allowing attackers to view the content of any file or webpage the webserver has access to.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24980.json, https://nvd.nist.gov/vuln/detail/CVE-2022-24980, https://typo3.org/help/security-advisories, https://typo3.org/security/advisory/typo3-ext-sa-2022-001
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
v3.3.3
v3.3.2
v3.3.1
v3.3.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
