CVE-2020-8091
Typo3 Cross-Site Scripting in Flash component (ELTS)
6.1
MEDIUM
CVSS 3.1
EPSS 5.2%
描述
svg.swf in TYPO3 6.2.0 to 6.2.38 ELTS and 7.0.0 to 7.1.0 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system. This may be at a contrib/websvg/svg.swf pathname.
如何修補 CVE-2020-8091
要修補 CVE-2020-8091,請將受影響套件升級到下列已修補版本。
- Bitnami/typo3—升級至 6.2.39 或更新版本
- —升級至 7.2.0 或更新版本
CVE-2020-8091 正在被利用嗎?
中等 — EPSS 為 5.2%,可持續追蹤但非最高優先。
受影響套件(2)
- >= 6.2.0, < 6.2.39, >= 7.0.0, < 7.1.0
- >= 7.0.0, < 7.2.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
參考連結(7)
- ADVISORYnvd.nist.gov/vuln/detail/CVE-2020-8091
- PATCHgithub.com/TYPO3/typo3
- WEBgithub.com/TYPO3/typo3/blob/4cb53e828bd5138d180cdf9cac1ccf7fd31086d2/typo3/sysext/core/Documentation/Changelog/7.2/Breaking-65962-WebSVGLibraryAndAPIRemoved.rst
- WEBgithub.com/TYPO3/typo3/commit/482e2e992f80f5e38cb48fcaea40fd9812a5252c