GHSA-p2jh-95jg-2w55
Information Disclosure in typo3/cms-install tool
Quick fix
GHSA-p2jh-95jg-2w55 — typo3/cms-install: upgrade to the fixed version with the command below.
composer require typo3/cms-install:^12.4.8Details
> ### CVSS: `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:F/RL:O/RC:C` (3.5)
### Problem The login screen of the standalone install tool discloses the full path of the transient data directory (e.g. _/var/www/html/var/transient/_). This applies to composer-based scenarios only - “classic” non-composer installations are not affected.
### Solution Update to TYPO3 version 12.4.8 that fixes the problem described above.
### Credits Thanks to Markus Klein who reported and fixed the issue.
### References * [TYPO3-CORE-SA-2023-005](https://typo3.org/security/advisory/typo3-core-sa-2023-005)
Are you affected?
Enter the version of the package you're using.
Affected packages
12.2.0Fixed in: 12.4.8composer require typo3/cms-install:^12.4.8References
- https://github.com/TYPO3/typo3/security/advisories/GHSA-p2jh-95jg-2w55[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-47126[ADVISORY]
- https://github.com/TYPO3/typo3/commit/1a735dac01ec7b337ed0d80c738caa8967dea423[WEB]
- https://github.com/TYPO3/typo3[PACKAGE]
- https://typo3.org/security/advisory/typo3-core-sa-2023-005[WEB]