TYPO3 Information Disclosure via Exception Handling/Logger
Description
Published to the GitHub Advisory Database
Jan 14, 2025
Reviewed
Jan 14, 2025
Published by the National Vulnerability Database
Jan 14, 2025
Last updated
Jan 14, 2025
Problem
It has been discovered that the install tool password has been logged as plaintext in case the password hashing mechanism used for the password was incorrect.
Solution
Update to TYPO3 versions 13.4.3 LTS that fixes the problem described.
Credits
Thanks to TYPO3 core & security team member Oliver Hader who reported and fixed the issue.
References
References