PT-2014-5626 · Typo3 · Typo3+1
Jan Kiesewetter
·
Publicado
2014-06-03
·
Atualizado
2022-05-17
·
CVE-2014-3946
CVSS v2.0
4.0
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
TYPO3 versions 6.2.0 through 6.2.2
Description
The query caching functionality in the Extbase Framework component does not properly validate group permissions, allowing remote authenticated users to read arbitrary queries. This issue is related to the failure to respect user groups of logged-in users when caching queries, which can lead to information disclosure. The query caching, introduced in Extbase 6.2, can present query results for a specific user group to a different group.
Recommendations
For TYPO3 versions 6.2.0 through 6.2.2, update to version 6.2.3 or later to resolve the issue. As a temporary workaround, consider disabling the query caching functionality in the Extbase Framework component until a patch is available. Restrict access to sensitive queries to minimize the risk of information disclosure.
Exploit
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Extbase Framework
Typo3