Skip to content

Typo3 Information Disclosure

Moderate severity GitHub Reviewed Published May 17, 2022 to the GitHub Advisory Database • Updated Apr 14, 2025

Package

composer typo3/cms (Composer)

Affected versions

>= 6.2.0, < 6.2.3

Patched versions

6.2.3

Description

Failing to respect user groups of logged in users when caching queries, Extbase is susceptible to information disclosure. The query caching (introduced in Extbase 6.2) used to cache queries that query results for a specific user group were presented to a different group.

References

Published by the National Vulnerability Database Jun 3, 2014
Published to the GitHub Advisory Database May 17, 2022
Reviewed Aug 16, 2023
Last updated Apr 14, 2025

Severity

Moderate

EPSS score

Exploit Prediction Scoring System (EPSS)

This score estimates the probability of this vulnerability being exploited within the next 30 days. Data provided by FIRST.
(36th percentile)

Weaknesses

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. Learn more on MITRE.

CVE ID

CVE-2014-3946

GHSA ID

GHSA-vccp-5v5h-p8m6

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.