CVE-2010-3664: Infoleak
Published Nov 4, 2019
·Updated
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Information Disclosure on the backend.
Affected Software
9 affected componentsFixes available
composer/typo3/cms-backend>=4.4.0<4.4.1
4.4.1
composer/typo3/cms-backend>=4.3.0<4.3.4
4.3.4
composer/typo3/cms-backend>=4.2.0<4.2.13
4.2.13
composer/typo3/cms-backend<4.1.14
4.1.14
debian/typo3-src
Typo3 TYPO3>=4.4.0<4.4.1
Typo3 TYPO3>=4.3.0<4.3.4
Typo3 TYPO3<4.1.14
Typo3 TYPO3>=4.2.0<4.2.13
Event History
Nov 4, 2019
CVE Published
via MITRE·09:21 PM
Data Sourced
via MITRE·09:21 PM
Description
Apr 21, 2022
Advisory Published
via GitHub·01:57 AM
Frequently Asked Questions
1
What is the severity of CVE-2010-3664?
CVE-2010-3664 is classified as a medium severity vulnerability due to its potential for information disclosure in the TYPO3 backend.
2
How do I fix CVE-2010-3664?
To fix CVE-2010-3664, upgrade TYPO3 to versions 4.1.14, 4.2.13, 4.3.4, or 4.4.1.
3
Which TYPO3 versions are affected by CVE-2010-3664?
CVE-2010-3664 affects TYPO3 versions before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4, and 4.4.x before 4.4.1.
4
What does CVE-2010-3664 allow attackers to do?
CVE-2010-3664 allows attackers to gain unauthorized access to sensitive information through the TYPO3 backend.
5
Is there a patch available for CVE-2010-3664?
Yes, TYPO3 provided patches in the updated versions to mitigate the information disclosure vulnerability described in CVE-2010-3664.