GHSA-38x7-cc6w-j27q

Suggest an improvement
Source
https://github.com/advisories/GHSA-38x7-cc6w-j27q
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/01/GHSA-38x7-cc6w-j27q/GHSA-38x7-cc6w-j27q.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-38x7-cc6w-j27q
Aliases
Published
2025-01-14T15:23:41Z
Modified
2025-01-14T22:21:48Z
Severity
  • 3.1 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
TYPO3 Information Disclosure via Exception Handling/Logger
Details

Problem

It has been discovered that the install tool password has been logged as plaintext in case the password hashing mechanism used for the password was incorrect.

Solution

Update to TYPO3 versions 13.4.3 LTS that fixes the problem described.

Credits

Thanks to TYPO3 core & security team member Oliver Hader who reported and fixed the issue.

References

Database specific
{
    "cwe_ids":  [
        "CWE-532"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-01-14T15:23:41Z",
    "nvd_published_at":  "2025-01-14T20:15:28Z",
    "severity":  "LOW"
}
References

Affected packages

Packagist / typo3/cms-install

Package

Name
typo3/cms-install
Purl
pkg:composer/typo3/cms-install

Affected ranges

Type
ECOSYSTEM
Events
Introduced
13.4.2
Fixed
13.4.3

Affected versions

13.*
13.4.2
v13.*
v13.4.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/01/GHSA-38x7-cc6w-j27q/GHSA-38x7-cc6w-j27q.json"