CVE-2022-23504: TYPO3 contains Sensitive Information Disclosure via YAML Placeholder Expressions in Site Configuration
> ### CVSS: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:L/E:F/RL:O/RC:C (5.3)
Problem Due to the lack of handling user-submitted YAML placeholder expressions in the site configuration backend module, attackers could expose sensitive internal information, such as system configuration or HTTP request messages of other website visitors.
A valid backend user account having administrator privileges is needed to exploit this vulnerability.
Solution Update to TYPO3 versions 9.5.38 ELTS, 10.4.33, 11.5.20, 12.1.1 that fix the problem described above.
Credits Thanks to TYPO3 core & security team member Oliver Hader who reported and fixed the issue.
References TYPO3-CORE-SA-2022-016
Other sources
TYPO3 is an open source PHP based web content management system. Versions prior to 9.5.38, 10.4.33, 11.5.20, and 12.1.1 are subject to Sensitive Information Disclosure. Due to the lack of handling user-submitted YAML placeholder expressions in the site configuration backend module, attackers could expose sensitive internal information, such as system configuration or HTTP request messages of other website visitors. A valid backend user account having administrator privileges is needed to exploit this vulnerability. This issue has been patched in versions 9.5.38 ELTS, 10.4.33, 11.5.20, 12.1.1.
— NVD
TYPO3-CORE-SA-2022-016: Sensitive Information Disclosure via YAML Placeholder Expressions in Site Configuration
Affected Software
Event History
Frequently Asked Questions
What is TYPO3-CORE-SA-2022-016?
TYPO3-CORE-SA-2022-016 is a vulnerability that allows sensitive information disclosure in TYPO3 versions prior to 9.5.38, 10.4.33, 11.5.20, and 12.1.1.
How does TYPO3-CORE-SA-2022-016 work?
TYPO3-CORE-SA-2022-016 works by exploiting the lack of handling user-submitted YAML placeholder expressions in the site configuration backend module.
What is the severity level of TYPO3-CORE-SA-2022-016?
TYPO3-CORE-SA-2022-016 has a severity level of medium (4.9).
How can I fix TYPO3-CORE-SA-2022-016?
To fix TYPO3-CORE-SA-2022-016, update TYPO3 to versions 9.5.38, 10.4.33, 11.5.20, or 12.1.1.
Where can I find more information about TYPO3-CORE-SA-2022-016?
More information about TYPO3-CORE-SA-2022-016 can be found at the TYPO3 security advisory page (https://typo3.org/security/advisory/typo3-core-sa-2022-016) and the TYPO3 GitHub security advisory page (https://github.com/TYPO3/typo3/security/advisories/GHSA-8w3p-qh3x-6gjr).