CVE-2020-26229
XML External Entity in Dashboard Widget
Description
### Problem It has been discovered that RSS widgets are susceptible to XML external entity processing. This vulnerability is reasonable, but is theoretical - it was not possible to actually reproduce the vulnerability with current PHP versions of supported and maintained system distributions. At least with _libxml2_ version 2.9, the processing of XML external entities is disabled per default - and cannot be exploited. Besides that, a valid backend user account is needed. ### Solution Update to TYPO3 version 10.4.10 that fixes the problem described.
How to fix CVE-2020-26229
To remediate CVE-2020-26229, upgrade the affected package to a fixed version below.
- —upgrade to 10.4.10 or later
- —upgrade to 10.4.10 or later
- —upgrade to 10.4.10 or later
Is CVE-2020-26229 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- >= 10.0.0, < 10.4.10
- >= 10.0.0, < 10.4.10
- >= 10.0.0, < 10.4.10
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | LOW3.7 | CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:L |