PT-2022-20485 · Typo3 · Typo3

Marco Huber

·

Published

2022-06-14

·

Updated

2024-03-06

·

CVE-2022-31047

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions TYPO3 versions prior to 7.6.57 ELTS TYPO3 versions prior to 8.7.47 ELTS TYPO3 versions prior to 9.5.34 ELTS TYPO3 versions prior to 10.4.29 TYPO3 versions prior to 11.5.11
Description System internal credentials or keys, such as database credentials, can be logged as plaintext in exception handlers when logging the complete exception stack trace.
Recommendations Update to TYPO3 version 7.6.57 ELTS or later Update to TYPO3 version 8.7.47 ELTS or later Update to TYPO3 version 9.5.34 ELTS or later Update to TYPO3 version 10.4.29 or later Update to TYPO3 version 11.5.11 or later

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Insertion into Log File

Weakness Enumeration

Related Identifiers

BIT-TYPO3-2022-31047
CVE-2022-31047
GHSA-FH99-4PGR-8J99

Affected Products

Typo3