TYPO3 is an open source web content management system. Prior to versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, and 11.5.11, system internal credentials or keys (e.g. database credentials) can be logged as plaintext in exception handlers, when logging the complete exception stack trace. TYPO3 versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, 11.5.11 contain a fix for the problem.
References
Link | Resource |
---|---|
https://github.com/TYPO3/typo3/commit/c93ea692e7dfef03b7c50fe5437487545bee4d6a | Patch Third Party Advisory |
https://github.com/TYPO3/typo3/security/advisories/GHSA-fh99-4pgr-8j99 | Third Party Advisory |
https://typo3.org/security/advisory/typo3-core-sa-2022-002 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: GitHub_M
Published: 2022-06-14T20:40:10
Updated: 2022-06-14T22:00:16
Reserved: 2022-05-18T00:00:00
Link: CVE-2022-31047
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-06-14T21:15:16.050
Modified: 2023-07-24T13:30:37.220
Link: CVE-2022-31047
JSON object: View
Redhat Information
No data.