The deferred_image_processing (aka Deferred image processing) extension before 1.0.2 for TYPO3 allows Denial of Service via the FAL API because of /var/transient disk consumption.
The product does not release or incorrectly releases a resource before it is made available for re-use.
Link | Tags |
---|---|
https://typo3.org/security/advisory/typo3-ext-sa-2021-009 | vendor advisory |