PT-2014-5626 · Typo3 · Typo3+1

Jan Kiesewetter

·

Publicado

2014-06-03

·

Atualizado

2022-05-17

·

CVE-2014-3946

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions TYPO3 versions 6.2.0 through 6.2.2
Description The query caching functionality in the Extbase Framework component does not properly validate group permissions, allowing remote authenticated users to read arbitrary queries. This issue is related to the failure to respect user groups of logged-in users when caching queries, which can lead to information disclosure. The query caching, introduced in Extbase 6.2, can present query results for a specific user group to a different group.
Recommendations For TYPO3 versions 6.2.0 through 6.2.2, update to version 6.2.3 or later to resolve the issue. As a temporary workaround, consider disabling the query caching functionality in the Extbase Framework component until a patch is available. Restrict access to sensitive queries to minimize the risk of information disclosure.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-3946
DSA-2942-1
GHSA-VCCP-5V5H-P8M6

Produtos afetados

Extbase Framework
Typo3