Medium severity5.3NVD Advisory· Published Feb 19, 2022· Updated Jun 17, 2026
CVE-2022-24979
CVE-2022-24979
Description
An issue was discovered in the Varnishcache extension before 2.0.1 for TYPO3. The Edge Site Includes (ESI) content element renderer component does not include an access check. This allows an unauthenticated user to render various content elements, resulting in insecure direct object reference (IDOR), with the potential of exposing internal content elements.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- TYPO3/Varnishcachedescription
- Range: <2.0.1
Patches
Vulnerability mechanics
References
2- typo3.org/security/advisory/typo3-ext-sa-2022-003nvdPatchVendor Advisory
- typo3.org/help/security-advisoriesnvdVendor Advisory
News mentions
0No linked articles in our index yet.