Wrong usage of the TYPO3 FAL API results in copies of processed files being saved to the /var/transient/ folder of a TYPO3 website on every frontend request. This can result in Denial of Service, since the webspace may be filled up with image files simply by crafting a large amount of requests to the website.
{ "nvd_published_at": "2021-08-13T17:15:00Z", "github_reviewed_at": "2021-08-30T17:19:44Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-404" ] }