Moderate severityNVD Advisory· Published Jun 3, 2014· Updated Jun 17, 2026
CVE-2014-3941
CVE-2014-3941
Description
TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, 6.1.0 before 6.1.9, and 6.2.0 before 6.2.3 allows remote attackers to have unspecified impact via a crafted HTTP Host header, related to "Host Spoofing."
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
typo3/cmsPackagist | >= 4.5.0, < 4.5.34 | 4.5.34 |
typo3/cmsPackagist | >= 4.7.0, < 4.7.19 | 4.7.19 |
typo3/cmsPackagist | >= 6.0.0, < 6.0.14 | 6.0.14 |
typo3/cmsPackagist | >= 6.1.0, < 6.1.9 | 6.1.9 |
typo3/cmsPackagist | >= 6.2.0, < 6.2.3 | 6.2.3 |
Affected products
83cpe:2.3:a:typo3:typo3:4.5.0:*:*:*:*:*:*:*+ 81 more
- cpe:2.3:a:typo3:typo3:4.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.10:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.11:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.12:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.13:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.14:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.15:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.16:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.17:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.18:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.19:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.20:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.21:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.22:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.23:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.24:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.25:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.26:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.27:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.28:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.29:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.30:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.31:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.32:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.33:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.3:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.4:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.5:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.6:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.7:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.8:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.5.9:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.7.0:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.7.10:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.7.11:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.7.12:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.7.13:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.7.14:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.7.15:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.7.16:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.7.17:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.7.18:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.7.1:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.7.2:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.7.3:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.7.4:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.7.5:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.7.6:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.7.7:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.7.8:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.7.9:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.0.12:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.0.13:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.0.9:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.0:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.1.8:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.1:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.2.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.2.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.2.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:6.2:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
11- typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2014-001/nvdVendor Advisory
- github.com/advisories/GHSA-594h-cx6w-p4jfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2014-3941ghsaADVISORY
- lists.opensuse.org/opensuse-security-announce/2016-08/msg00028.htmlnvdWEB
- lists.opensuse.org/opensuse-updates/2014-06/msg00037.htmlnvdWEB
- lists.opensuse.org/opensuse-updates/2016-08/msg00083.htmlnvdWEB
- typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2014-001ghsaWEB
- www.debian.org/security/2014/dsa-2942nvdWEB
- www.openwall.com/lists/oss-security/2014/06/03/2nvdWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/CVE-2014-3941.yamlghsaWEB
- typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2014-001ghsaWEB
News mentions
0No linked articles in our index yet.