Author: Oliver Hader
Oliver started to work with TYPO3 in 2005 and was fascinated by the product and its universe. Since 2007 he is member of the TYPO3 Core Team. After going back to university in 2014 for achieving a postgraduate master degree in internet web science, he is now researching on advanced web technology topics in general and for TYPO3 in particular. In his spare time, Oliver loves to go cycling cross-country in the uplands around Hof (Germany) in northern Bavaria - at the region where he's living as well.
- Developer & Technology
- Public Service Announcement
TYPO3-PSA-2019-011: Possible Insecure Deserialization in Extbase Request Handling
-
Oliver Hader
It has been discovered that TYPO3 CMS can be vulnerable to insecure deserialization.
Read more- Developer & Technology
- Public Service Announcement
TYPO3-PSA-2019-010: Cross-Site Scripting Vulnerabilities in File Upload Handling
-
Oliver Hader
It has been discovered that TYPO3 is susceptible to cross-site scripting.
- Showcase & Success
- Public Service Announcement
TYPO3-PSA-2019-009: Truncated passwords during authentication process on typo3.org services
-
Oliver Hader
It has been discovered that passwords were truncated during authentication process on typo3.org services.
- Developer & Technology
- Product Updates & Roadmap
TYPO3 v9.5.10 LTS and v8.7.28 LTS released
-
Oliver Hader
The TYPO3 Community announces versions 9.5.10 LTS and 8.7.28 LTS of the TYPO3 Enterprise Content Management System.
- Developer & Technology
- TYPO3 CMS
TYPO3-CORE-SA-2019-018: Security Misconfiguration in Frontend Session Handling
-
Oliver Hader
It has been discovered, that TYPO3 CMS is susceptible to security misconfiguration.
- Developer & Technology
- TYPO3 CMS
TYPO3-CORE-SA-2019-017: Broken Access Control in Import Module
-
Oliver Hader
It has been discovered, that TYPO3 CMS is susceptible to broken access control.
- Developer & Technology
- Public Service Announcement
TYPO3-PSA-2019-008: By-passing protection of Phar Stream Wrapper Interceptor
-
Oliver Hader
It has been discovered that the protection against insecure deserialization can be by-passed in Phar Stream Wrapper component.
- Developer & Technology
- Public Service Announcement
TYPO3-PSA-2019-007: By-passing protection of Phar Stream Wrapper Interceptor
-
Oliver Hader
It has been discovered that the protection against insecure deserialization can be by-passed in Phar Stream Wrapper component.
- Developer & Technology
- Public Service Announcement
TYPO3-PSA-2019-006: Security Misconfiguration since TYPO3 9.4.0
-
Oliver Hader
It has been discovered that TYPO3 is susceptible to security misconfiguration.
- Developer & Technology
- Public Service Announcement
TYPO3-PSA-2019-005: Cross-Site Scripting in Bootstrap CSS toolkit before 3.4.1 and 4.3.0
-
Oliver Hader
It has been discovered that 3rd party library Bootstrap CSS toolkit bundled with TYPO3 is vulnerable to cross-site scripting through prototype pollution.