MEDIUM5.3
GHSA-f624-8hfq-5fh3
TYPO3 Information Disclosure of Installed Extensions
Quick fix
GHSA-f624-8hfq-5fh3 — typo3/cms: upgrade to the fixed version with the command below.
composer require typo3/cms:^8.7.23Details
It has been discovered that mechanisms used for configuration of RequireJS package loading are susceptible to information disclosure. This way a potential attack can retrieve additional information about installed system and third party extensions.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/TYPO3/typo3/commit/889ed77d2905d8b17afd31c723a23240c978823f[WEB]
- https://github.com/TYPO3/typo3/commit/c81cca9e419e7aaed551b9b9a8d012ba7bffb287[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/2019-01-22-1.yaml[WEB]
- https://github.com/TYPO3/typo3[PACKAGE]
- https://typo3.org/security/advisory/typo3-core-sa-2019-001[WEB]