CVE-2023-47126

TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions the login screen of the standalone install tool discloses the full path of the transient data directory (e.g. /var/www/html/var/transient/). This applies to composer-based scenarios only - “classic” non-composer installations are not affected. This issue has been addressed in version 12.4.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*

History

21 Nov 2023, 03:01

Type Values Removed Values Added
First Time Typo3 typo3
Typo3
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
References () https://github.com/TYPO3/typo3/security/advisories/GHSA-p2jh-95jg-2w55 - () https://github.com/TYPO3/typo3/security/advisories/GHSA-p2jh-95jg-2w55 - Vendor Advisory
References () https://github.com/TYPO3/typo3/commit/1a735dac01ec7b337ed0d80c738caa8967dea423 - () https://github.com/TYPO3/typo3/commit/1a735dac01ec7b337ed0d80c738caa8967dea423 - Patch
References () https://typo3.org/security/advisory/typo3-core-sa-2023-005 - () https://typo3.org/security/advisory/typo3-core-sa-2023-005 - Vendor Advisory

14 Nov 2023, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-14 20:15

Updated : 2023-12-10 15:26


NVD link : CVE-2023-47126

Mitre link : CVE-2023-47126

CVE.ORG link : CVE-2023-47126


JSON object : View

Products Affected

typo3

  • typo3
CWE
NVD-CWE-noinfo CWE-200

Exposure of Sensitive Information to an Unauthorized Actor