VulnerabilityModified
CVE-2014-3941
TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, 6.1.0 before 6.1.9, and 6.2.0 before 6.2.3 allows remote attackers to have unspecified impact via a crafted HTTP Host header, related to "Host Spoofing."
MEDIUM 5.0EPSS 2.71%
Does this matter?
Lower severity and a low EPSS score (2.71%). Track it; it rarely justifies an emergency change on its own.
Description
TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, 6.1.0 before 6.1.9, and 6.2.0 before 6.2.3 allows remote attackers to have unspecified impact via a crafted HTTP Host header, related to "Host Spoofing."
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 2.71% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- typo3/typo3
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00028.html
- http://lists.opensuse.org/opensuse-updates/2014-06/msg00037.html
- http://lists.opensuse.org/opensuse-updates/2016-08/msg00083.html
- http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2014-001/Vendor Advisory
- http://www.debian.org/security/2014/dsa-2942
- http://www.openwall.com/lists/oss-security/2014/06/03/2
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00028.html
- http://lists.opensuse.org/opensuse-updates/2014-06/msg00037.html
- http://lists.opensuse.org/opensuse-updates/2016-08/msg00083.html
- http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2014-001/Vendor Advisory
- http://www.debian.org/security/2014/dsa-2942
- http://www.openwall.com/lists/oss-security/2014/06/03/2
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.