Information disclosure in TYPO3 - CVE-2014-3946

 

Information disclosure in TYPO3 - CVE-2014-3946

Published: June 3, 2014 / Updated: August 10, 2020


Vulnerability identifier: #VU41581
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2014-3946
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: TYPO3
Affected software:
TYPO3

Detailed vulnerability description

The vulnerability allows a remote #AU# to gain access to sensitive information.

The query caching functionality in the Extbase Framework component in TYPO3 6.2.0 before 6.2.3 does not properly validate group permissions, which allows remote authenticated users to read arbitrary queries via unspecified vectors.


How to mitigate CVE-2014-3946

Install update from vendor's website.

Sources