Requesting invalid or non-existing resources via HTTP triggers the page error handler, which again could retrieve content to be shown as an error message from another page. This leads to a scenario in which the application is calling itself recursively - amplifying the impact of the initial attack until the limits of the web server are exceeded.
This vulnerability is very similar, but not identical, to the one described in TYPO3-CORE-SA-2021-005 (CVE-2021-21359).
Update to TYPO3 versions 9.5.38 ELTS, 10.4.33 or 11.5.20 that fix the problem described above.
{ "nvd_published_at": "2022-12-14T08:15:00Z", "github_reviewed_at": "2022-12-13T17:02:09Z", "severity": "MODERATE", "github_reviewed": true, "cwe_ids": [ "CWE-405", "CWE-674" ] }