Skip to main navigation Skip to main content Skip to page footer

Improper Access Control in WebDav for filemounts (webdav)

It has been discovered that the extension "WebDav for filemounts" (webdav) is susceptible to Improper Access Control.

Release Date: November 27, 2014

Component Type: Third party extension. This extension is not a part of the TYPO3 default installation.

Affected Versions: 2.0.0

Vulnerability Type: Improper Access Control

Severity: Medium

Suggested CVSS v2.0: AV:N/AC:L/Au:S/C:P/I:P/A:N/E:H/RL:OF/RC:C

Problem Description: The extension fails to restrict resource-access via webdav protocol to only those resources the backend user has been granted access to.

Solution: Updated version 2.0.1 is available from the TYPO3 extension manager and at http://typo3.org/extensions/repository/download/webdav/2.0.1/t3x/.

Credits: Credits go to extension maintainer Kay Strobach who discovered and reported the issue.

 

 

General advice: Follow the recommendations that are given in the TYPO3 Security Guide. Please subscribe to the typo3-announce mailing list to receive future Security Bulletins via E-mail.