LOW3.1
GHSA-38x7-cc6w-j27q
TYPO3 Information Disclosure via Exception Handling/Logger
Quick fix
GHSA-38x7-cc6w-j27q — typo3/cms-install: upgrade to the fixed version with the command below.
composer require typo3/cms-install:^13.4.3Details
### Problem It has been discovered that the install tool password has been logged as plaintext in case the password hashing mechanism used for the password was incorrect.
### Solution Update to TYPO3 versions 13.4.3 LTS that fixes the problem described.
### Credits Thanks to TYPO3 core & security team member Oliver Hader who reported and fixed the issue.
### References * [TYPO3-CORE-SA-2025-001](https://typo3.org/security/advisory/typo3-core-sa-2025-001)
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/typo3/cms-install
Introduced in:
13.4.2Fixed in: 13.4.3Fix
composer require typo3/cms-install:^13.4.3References
- https://github.com/TYPO3/typo3/security/advisories/GHSA-38x7-cc6w-j27q[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-55891[ADVISORY]
- https://github.com/TYPO3-CMS/install/commit/baa8089b1baf5552fab213a5761081608b0afc51[WEB]
- https://github.com/TYPO3-CMS/install[PACKAGE]
- https://typo3.org/security/advisory/typo3-core-sa-2025-001[WEB]