It has been discovered that backend user settings (in $BE_USER->uc) are vulnerable to insecure deserialization. In combination with vulnerabilities of 3rd party components this can lead to remote code execution. A valid backend user account is needed to exploit this vulnerability.
Update to TYPO3 versions 9.5.17 or 10.4.2 that fix the problem described.
{
"severity": "HIGH",
"github_reviewed_at": "2020-05-13T23:28:47Z",
"cwe_ids": [
"CWE-502"
],
"nvd_published_at": null,
"github_reviewed": true
}