Non-encrypted confidential information In typo3/cms-install
Description
TYPO3 Information Disclosure via Exception Handling/Logger
Problem
It has been discovered that the install tool password has been logged as plaintext in case the password hashing mechanism used for the password was incorrect.
Solution
Update to TYPO3 versions 13.4.3 LTS that fixes the problem described.
Credits
Thanks to TYPO3 core & security team member Oliver Hader who reported and fixed the issue.
References
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 13.4.3 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.