Lucene search

K
typo3TYPO3 AssociationTYPO3-EXT-SA-2018-003
HistoryAug 09, 2018 - 12:00 a.m.

Environment Variable Injection in extension "Amazon AWS S3 FAL driver (CDN)" (aus_driver_amazon_s3)

2018-08-0900:00:00
TYPO3 Association
typo3.org
75

EPSS

0.928

Percentile

99.1%

The extension uses an old version of the third party library guzzlehttp/guzzle, which is known to be vulnerable against the HTTPOXY attack. Read <https://www.symfony.fi/entry/httpoxy-vulnerability-hits-php-installations-using-fastcgi-and-php-fpm-and-hhvm&gt; or <https://httpoxy.org/&gt; for further details.