Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. typo3/cms
  4. ›
  5. GHSA-pw2q-qwvj-gh43

GHSA-pw2q-qwvj-gh43: Cache Flooding in TYPO3 Frontend

June 5, 2024

Links with a valid cHash argument lead to newly generated page cache entries. Because the cHash is not bound to a specific page, attackers could use valid cHash arguments for multiple pages, leading to additional useless page cache entries. Depending on the number of pages in the system and the number of available valid links with a cHash, attackers could add a considerable amount of additional cache entries, which in the end exceed storage limits and thus could lead to the system not responding any more. This means the Cache Flooding attack potentially could lead to a successful Denial of Service (DoS) attack.

References

  • github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/2016-09-14-2.yaml
  • github.com/advisories/GHSA-pw2q-qwvj-gh43

Code Behaviors & Features

Detect and mitigate GHSA-pw2q-qwvj-gh43 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 6.2.0 before 6.2.27, all versions starting from 7.6.0 before 7.6.11, all versions starting from 8.0.0 before 8.3.1

Fixed versions

  • 6.2.27
  • 7.6.11
  • 8.3.1

Solution

Upgrade to versions 6.2.27, 7.6.11, 8.3.1 or above.

Impact 5.3 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Learn more about CVSS

Source file

packagist/typo3/cms/GHSA-pw2q-qwvj-gh43.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:32 +0000.