CVE-2024-55891

Source
https://cve.org/CVERecord?id=CVE-2024-55891
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-55891.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-55891
Aliases
Published
2025-01-14T19:11:58.861Z
Modified
2026-08-12T03:51:10.907829171Z
Severity
  • 3.1 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Information Disclosure via Exception Handling/Logger in TYPO3
Details

TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has been logged as plaintext in case the password hashing mechanism used for the password was incorrect. Users are advised to update to TYPO3 versions 13.4.3 ELTS which fixes the problem described. There are no known workarounds for this vulnerability.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-532"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/55xxx/CVE-2024-55891.json"
}
References

Affected packages

Git / github.com/typo3/typo3

Affected ranges

Type
GIT
Repo
https://github.com/typo3/typo3
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "13.4.3"
        },
        {
            "introduced": "13.4.2"
        },
        {
            "last_affected": "13.4.2"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_STRING"
    ],
    "cpe": "cpe:2.3:a:typo3:typo3:13.4.2:*:*:*:*:*:*:*"
}

Affected versions

13.*
13.4.2
v13.*
v13.4.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-55891.json"