Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rf5m-h8q9-9w6q

Опубликовано: 08 окт. 2024
Источник: github
Github: Прошло ревью
CVSS4: 2.3
CVSS3: 3.1

Описание

Information Disclosure in TYPO3 Page Tree

Problem

Backend users could see items in the backend page tree without having access if the mounts pointed to pages restricted for their user/group, or if no mounts were configured but the pages allowed access to "everybody." However, affected users could not manipulate these pages.

Solution

Update to TYPO3 versions 10.4.46 ELTS, 11.5.40 LTS, 12.4.21 LTS, 13.3.1 that fix the problem described.

Credits

Thanks to Peter Schuler who reported this issue and to TYPO3 core & security team member Oliver Hader who fixed the issue.

Пакеты

Наименование

typo3/cms-backend

composer
Затронутые версииВерсия исправления

>= 13.0.0, < 13.3.1

13.3.1

Наименование

typo3/cms-backend

composer
Затронутые версииВерсия исправления

>= 12.0.0, < 12.4.21

12.4.21

Наименование

typo3/cms-backend

composer
Затронутые версииВерсия исправления

>= 11.0.0, < 11.5.40

11.5.40

Наименование

typo3/cms-backend

composer
Затронутые версииВерсия исправления

>= 10.0.0, < 10.4.46

10.4.46

EPSS

Процентиль: 41%
0.00193
Низкий

2.3 Low

CVSS4

3.1 Low

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 3.1
nvd
больше 1 года назад

TYPO3 is a free and open source Content Management Framework. Backend users could see items in the backend page tree without having access if the mounts pointed to pages restricted for their user/group, or if no mounts were configured but the pages allowed access to "everybody." However, affected users could not manipulate these pages. Users are advised to update to TYPO3 versions 10.4.46 ELTS, 11.5.40 LTS, 12.4.21 LTS, 13.3.1 that fix the problem described. There are no known workarounds for this vulnerability.

EPSS

Процентиль: 41%
0.00193
Низкий

2.3 Low

CVSS4

3.1 Low

CVSS3

Дефекты

CWE-863