Impact
The SYSSY extension fails to verify the expiration field on client‑supplied JSON Web Tokens, which enables an attacker who already controls a valid API key to use an expired token for authentication. This bypasses the intended lifetime restriction and can allow continued access to the protected API beyond the intended timeframe, potentially enabling unauthorized actions within the TYPO3 environment.
Affected Systems
TYPO3 installations that have the SYSSY – TYPO3 Monitoring & Security Checks extension installed are affected. Specific version information is not provided in the advisory, so all deployed versions of the extension are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available. This vulnerability is not listed in the CISA KEV catalog. Exploitation requires possession of a valid API key for the SYSSY project; after that, the attacker can authenticate with an expired token through the API endpoint. No additional privileges or local compromise are required to leverage this flaw.
OpenCVE Enrichment