CVE-2012-3529: Infoleak
Published Sep 5, 2012
·Updated
The configuration module in the backend in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to obtain the encryption key via unspecified vectors.
Affected Software
41 affected componentsFixes available
composer/typo3/cms>=4.7<4.7.4
4.7.4
composer/typo3/cms>=4.6<4.6.12
4.6.12
composer/typo3/cms>=4.5<4.5.19
4.5.19
Typo3 TYPO3=4.5
Typo3 TYPO3=4.5.0
Typo3 TYPO3=4.5.1
Typo3 TYPO3=4.5.2
Typo3 TYPO3=4.5.3
Typo3 TYPO3=4.5.4
Typo3 TYPO3=4.5.5
Typo3 TYPO3=4.5.6
Typo3 TYPO3=4.5.7
Typo3 TYPO3=4.5.8
Typo3 TYPO3=4.5.9
Typo3 TYPO3=4.5.10
Typo3 TYPO3=4.5.11
Typo3 TYPO3=4.5.12
Typo3 TYPO3=4.5.13
Typo3 TYPO3=4.5.14
Typo3 TYPO3=4.5.15
Typo3 TYPO3=4.5.16
Typo3 TYPO3=4.5.17
Typo3 TYPO3=4.5.18
Typo3 TYPO3=4.6
Typo3 TYPO3=4.6.0
Typo3 TYPO3=4.6.1
Typo3 TYPO3=4.6.2
Typo3 TYPO3=4.6.3
Typo3 TYPO3=4.6.4
Typo3 TYPO3=4.6.5
Typo3 TYPO3=4.6.6
Typo3 TYPO3=4.6.7
Typo3 TYPO3=4.6.8
Typo3 TYPO3=4.6.9
Typo3 TYPO3=4.6.10
Typo3 TYPO3=4.6.11
Typo3 TYPO3=4.7
Typo3 TYPO3=4.7.0
Typo3 TYPO3=4.7.1
Typo3 TYPO3=4.7.2
Typo3 TYPO3=4.7.3
Event History
Sep 5, 2012
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·01:43 AM
Frequently Asked Questions
1
What is the severity of CVE-2012-3529?
The severity of CVE-2012-3529 is considered high due to the risk of exposing sensitive encryption keys to remote authenticated users.
2
How do I fix CVE-2012-3529?
To fix CVE-2012-3529, update TYPO3 to version 4.5.19, 4.6.12, or 4.7.4 or later.
3
Which versions of TYPO3 are affected by CVE-2012-3529?
CVE-2012-3529 affects TYPO3 versions 4.5.x prior to 4.5.19, 4.6.x prior to 4.6.12, and 4.7.x prior to 4.7.4.
4
What type of vulnerability is CVE-2012-3529?
CVE-2012-3529 is a security vulnerability that allows unauthorized exposure of encryption keys.
5
Can CVE-2012-3529 be exploited remotely?
Yes, CVE-2012-3529 can be exploited by remote authenticated backend users.