Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p2jh-95jg-2w55

Опубликовано: 14 нояб. 2023
Источник: github
Github: Прошло ревью
CVSS3: 3.7

Описание

Information Disclosure in typo3/cms-install tool

CVSS: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:F/RL:O/RC:C (3.5)

Problem

The login screen of the standalone install tool discloses the full path of the transient data directory (e.g. /var/www/html/var/transient/). This applies to composer-based scenarios only - “classic” non-composer installations are not affected.

Solution

Update to TYPO3 version 12.4.8 that fixes the problem described above.

Credits

Thanks to Markus Klein who reported and fixed the issue.

References

Пакеты

Наименование

typo3/cms-install

composer
Затронутые версииВерсия исправления

>= 12.2.0, < 12.4.8

12.4.8

EPSS

Процентиль: 44%
0.00213
Низкий

3.7 Low

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 3.7
nvd
около 2 лет назад

TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions the login screen of the standalone install tool discloses the full path of the transient data directory (e.g. /var/www/html/var/transient/). This applies to composer-based scenarios only - “classic” non-composer installations are not affected. This issue has been addressed in version 12.4.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.

EPSS

Процентиль: 44%
0.00213
Низкий

3.7 Low

CVSS3

Дефекты

CWE-200