FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-04-18 11:12:36 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
0eab001a-9708-11ec-96c9-589cfc0f81b0typo3 -- XSS vulnerability in svg-sanitize

The TYPO3 project reports:

The SVG sanitizer library enshrined/svg-sanitize before version 0.15.0 did not remove HTML elements wrapped in a CDATA section. As a result, SVG content embedded in HTML (fetched as text/html) was susceptible to cross-site scripting. Plain SVG files (fetched as image/svg+xml) were not affected.


Discovery 2022-02-22
Entry 2022-02-27
typo3-10-php74
< 10.4.25

typo3-11-php74
typo3-11-php80
typo3-11-php81
< 11.5.7

CVE-2022-23638
https://github.com/typo3/typo3/commit/9940defb21
https://typo3.org/article/typo3-psa-2022-001
d9e154c9-7de9-11ed-adca-080027d3a315typo3 -- multiple vulnerabilities

TYPO3 reports:

TYPO3-CORE-SA-2022-012: Denial of Service in Page Error Handling.

TYPO3-CORE-SA-2022-013: Weak Authentication in Frontend Login.

TYPO3-CORE-SA-2022-014: Insufficient Session Expiration after Password Reset.

TYPO3-CORE-SA-2022-015: Arbitrary Code Execution via Form Framework.

TYPO3-CORE-SA-2022-016: Sensitive Information Disclosure via YAML Placeholder Expressions in Site Configuration.

TYPO3-CORE-SA-2022-017: By-passing Cross-Site Scripting Protection in HTML Sanitizer.


Discovery 2022-12-13
Entry 2022-12-17
typo3-11-php81
< 11.5.20

typo3-12-php81
< 12.1.2

CVE-2022-23499
CVE-2022-23500
CVE-2022-23501
CVE-2022-23502
CVE-2022-23503
CVE-2022-23504
https://typo3.org/article/typo3-1211-11520-and-10433-security-releases-published