TYPO3 PharStreamWrapper 2.1.0

CPE Details

TYPO3 PharStreamWrapper 2.1.0
2.1.0
2019-09-10
15h12 +00:00
2019-09-10
15h12 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:typo3:pharstreamwrapper:2.1.0:*:*:*:*:*:*:*

Informations

Vendor

typo3

Product

pharstreamwrapper

Version

2.1.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2019-11831 2019-05-09 01h52 +00:00 The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL.
9.8
Critical
CVE-2019-11830 2019-05-09 01h51 +00:00 PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attackers to bypass a deserialization protection mechanism.
9.8
Critical