GHSA-34jq-548x-m2x9

    Dashboard / Vulnerabilities / GHSA-34jq-548x-m2x9

    GHSA-34jq-548x-m2x9

    Published: 30 Aug 2021Last Modified: 8 Nov 2023

    Summary: Improper Resource Shutdown or Release in TYPO3 extension

    Details: Wrong usage of the TYPO3 FAL API results in copies of processed files being saved to the /var/transient/ folder of a TYPO3 website on every frontend request. This can result in Denial of Service, since the webspace may be filled up with image files simply by crafting a large amount of requests to the website.

    Affected packages

    Package

    Name: webcoast/deferred-image-processing

    Purl: pkg:composer/webcoast/deferred-image-processing

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.0.2

    Affected versions

    1.0.0
    1.0.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-34jq-548x-m2x9 | CVE-DB