Impact
The vulnerability arises in the Apache Solr for TYPO3 extension, which forces empty frontend-group and subpage‑inheritance restrictions onto page records during indexer sub‑requests. This forged state is then stored in the shared rootline cache, enabling anonymous visitors to bypass extendToSubpages‑inherited access restrictions on cached pages. As a result, non‑authenticated users can read content that should otherwise be protected, compromising confidentiality and potentially revealing sensitive information.
Affected Systems
TYPO3 sites that have installed the "Apache Solr for TYPO3 - Enterprise Search" extension are affected. No specific version ranges are listed in the advisory, but any installation using this extension may be vulnerable until a fix is applied.
Risk and Exploitability
The vulnerability carries a CVSS v3.1 base score of 7.6, indicating high severity. EPSS data is not available and the issue is not listed in CISA KEV catalog, but the lack of exploitation metrics does not mean the risk is low. The likely attack vector is a remote request that triggers the extension’s indexer, which then writes the forged page state into the cache. The persistent cache entries allow anonymous visitors to repeatedly obtain access to protected content until the cache is purged or the vulnerability is patched.
OpenCVE Enrichment