TYPO3 Varnishcache
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*
- <= 2.0.0
A vulnerability allowing insecure direct object reference (IDOR) has been identified in the Varnishcache extension for TYPO3, prior to version 2.0.1. The issue arises in the Edge Site Includes (ESI) content element renderer component, which lacks an access check. This flaw enables unauthenticated users to render various content elements, potentially exposing internal content.
Exploitation of this vulnerability could lead to unauthorized access to and exposure of internal content elements through the ESI content element renderer.
Users are advised to update the Varnishcache extension to version 2.0.1, available through the TYPO3 extension manager, Packagist, or the TYPO3 Extension Repository.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.