VDB
Sign up
HIGH

GHSA-w2pf-7q5w-2cgw

TYPO3 Workspaces Module Information Disclosure

Quick fix

GHSA-w2pf-7q5w-2cgw — typo3/cms-workspaces: upgrade to the fixed version with the command below.

composer require typo3/cms-workspaces:^12.4.37

Details

Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke the corresponding AJAX backend route to disclose sensitive information without having access.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/typo3/cms-workspaces
Introduced in: 9.0.0Fixed in: 12.4.37
Fixcomposer require typo3/cms-workspaces:^12.4.37
Packagist/typo3/cms-workspaces
Introduced in: 10.0.0Fixed in: 12.4.37
Fixcomposer require typo3/cms-workspaces:^12.4.37
Packagist/typo3/cms-workspaces
Introduced in: 11.0.0Fixed in: 12.4.37
Fixcomposer require typo3/cms-workspaces:^12.4.37
Packagist/typo3/cms-workspaces
Introduced in: 12.0.0Fixed in: 12.4.37
Fixcomposer require typo3/cms-workspaces:^12.4.37
Packagist/typo3/cms-workspaces
Introduced in: 13.0.0Fixed in: 13.4.18
Fixcomposer require typo3/cms-workspaces:^13.4.18

References