FreeBSD : typo3 -- multiple vulnerabilities (eab964f8-d632-11ea-9172-4c72b94353b5)

high Nessus Plugin ID 139349

Language:

Synopsis

The remote FreeBSD host is missing one or more security-related updates.

Description

Typo3 Team reports :

In case an attacker manages to generate a valid cryptographic message authentication code (HMAC-SHA1) - either by using a different existing vulnerability or in case the internal encryptionKey was exposed - it is possible to retrieve arbitrary files of a TYPO3 installation. This includes the possibility to fetch typo3conf/LocalConfiguration.php which again contains the encryptionKey as well as credentials of the database management system being used. In case a database server is directly accessible either via internet or in a shared hosting network, this allows to completely retrieve, manipulate or delete database contents. This includes creating an administration user account - which can be used to trigger remote code execution by injecting custom extensions.

It has been discovered that an internal verification mechanism can be used to generate arbitrary checksums. This allows to inject arbitrary data having a valid cryptographic message authentication code (HMAC-SHA1) and can lead to various attack chains as described below.

Solution

Update the affected packages.

See Also

http://www.nessus.org/u?b777e1db

https://typo3.org/security/advisory/typo3-core-sa-2020-007

https://typo3.org/security/advisory/typo3-core-sa-2020-008

http://www.nessus.org/u?bcaed38b

Plugin Details

Severity: High

ID: 139349

File Name: freebsd_pkg_eab964f8d63211ea91724c72b94353b5.nasl

Version: 1.3

Type: local

Published: 8/6/2020

Updated: 5/12/2022

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2020-15099

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2020-15098

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:typo3-10-php72, p-cpe:/a:freebsd:freebsd:typo3-10-php73, p-cpe:/a:freebsd:freebsd:typo3-10-php74, p-cpe:/a:freebsd:freebsd:typo3-9-php72, p-cpe:/a:freebsd:freebsd:typo3-9-php73, p-cpe:/a:freebsd:freebsd:typo3-9-php74, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Exploit Ease: No known exploits are available

Patch Publication Date: 8/4/2020

Vulnerability Publication Date: 7/28/2020

Reference Information

CVE: CVE-2020-15098, CVE-2020-15099