CVE-2010-3673: Infoleak
Published Nov 5, 2019
·Updated
TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows information disclosure in the mail header of the HTML mailing API.
Affected Software
7 affected componentsFixes available
composer/typo3/cms-core>=4.4<4.4.1
4.4.1
composer/typo3/cms-core>=4.3<4.3.4
4.3.4
composer/typo3/cms-core<4.2.13
4.2.13
debian/typo3-src
Typo3 TYPO3>=4.4.0<4.4.1
Typo3 TYPO3>=4.3.0<4.3.4
Typo3 TYPO3>=4.2.0<4.2.13
Event History
Nov 5, 2019
CVE Published
via MITRE·07:32 PM
Data Sourced
via MITRE·07:32 PM
Description
Apr 21, 2022
Advisory Published
via GitHub·01:57 AM
Frequently Asked Questions
1
What is the severity of CVE-2010-3673?
CVE-2010-3673 is classified as a medium severity vulnerability due to its potential for information disclosure.
2
How do I fix CVE-2010-3673?
To fix CVE-2010-3673, upgrade to TYPO3 versions 4.4.1, 4.3.4, or 4.2.13 or later.
3
What types of software are affected by CVE-2010-3673?
CVE-2010-3673 affects TYPO3 versions earlier than 4.4.1, 4.3.4, and 4.2.13.
4
What does CVE-2010-3673 allow an attacker to do?
CVE-2010-3673 allows an attacker to achieve information disclosure through the mail header of the HTML mailing API.
5
Is there a workaround for CVE-2010-3673?
There is no official workaround for CVE-2010-3673; the recommended solution is to upgrade to a patched version.