First published: Thu May 22 2014(Updated: )
Failing to respect user groups of logged in users when caching queries, Extbase is susceptible to information disclosure. The query caching (introduced in Extbase 6.2) used to cache queries that query results for a specific user group were presented to a different group.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/typo3/cms | >=6.2.0<6.2.3 | |
composer/typo3/cms | >=6.2.0<6.2.3 | 6.2.3 |
TYPO3 | =6.2 | |
TYPO3 | =6.2.0-beta1 | |
TYPO3 | =6.2.0-beta2 | |
TYPO3 | =6.2.0-beta3 | |
TYPO3 | =6.2.1 | |
TYPO3 | =6.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3946 has a medium severity level due to the potential for information disclosure.
To fix CVE-2014-3946, upgrade TYPO3 CMS to version 6.2.3 or later.
CVE-2014-3946 affects TYPO3 CMS versions from 6.2.0 to 6.2.2.
Exploitation of CVE-2014-3946 can lead to unauthorized access to information intended for other user groups.
Yes, a patch is available by upgrading to TYPO3 CMS version 6.2.3.