Oliver started to work with TYPO3 in 2005 and was fascinated by the product and its universe. Since 2007 he is member of the TYPO3 Core Team. After going back to university in 2014 for achieving a postgraduate master degree in internet web science, he is now researching on advanced web technology topics in general and for TYPO3 in particular. In his spare time, Oliver loves to go cycling cross-country in the uplands around Hof (Germany) in northern Bavaria - at the region where he's living as well.
TYPO3-PSA-2019-007: By-passing protection of Phar Stream Wrapper Interceptor
It has been discovered that the protection against insecure deserialization can be by-passed in Phar Stream Wrapper component.
Read moreTYPO3-PSA-2019-006: Security Misconfiguration since TYPO3 9.4.0
It has been discovered that TYPO3 is susceptible to security misconfiguration.
TYPO3-PSA-2019-005: Cross-Site Scripting in Bootstrap CSS toolkit before 3.4.1 and 4.3.0
It has been discovered that 3rd party library Bootstrap CSS toolkit bundled with TYPO3 is vulnerable to cross-site scripting through prototype pollution.
TYPO3-PSA-2019-004: Cross-Site Scripting in jQuery before 3.4.0
It has been discovered that 3rd party library jQuery bundled with TYPO3 is vulnerable to cross-site scripting through prototype pollution.
- Developer & Technology
- Security / TYPO3 CMS
TYPO3-CORE-SA-2019-013: Cross-Site Scripting in Fluid Engine
It has been discovered, that TYPO3 CMS is vulnerable to cross-site scripting.
- Developer & Technology
- Security / TYPO3 CMS
TYPO3-CORE-SA-2019-012: Possible Arbitrary Code Execution in Image Processing
It has been discovered, that TYPO3 CMS is vulnerable to arbitrary code execution.
- Developer & Technology
- Security / TYPO3 CMS
TYPO3-CORE-SA-2019-011: Security Misconfiguration in User Session Handling
It has been discovered, that TYPO3 CMS is susceptible to security misconfiguration.
- Developer & Technology
- Security / TYPO3 CMS
TYPO3-CORE-SA-2019-010: Information Disclosure in User Authentication
It has been discovered, that TYPO3 CMS is susceptible to information disclosure.
- Developer & Technology
- Security / TYPO3 CMS
TYPO3-CORE-SA-2019-009: Information Disclosure in Page Tree
It has been discovered, that TYPO3 CMS is susceptible to information disclosure.
Persistence Initiative: Meeting Report
During a weekend in March 2019 Artus Kolanowski, Manuel Selbach, Benni Mack and Oliver Hader have been meeting at dkd Offices in Frankfurt/DE for a persistence initiative code and concept sprint.