First published: Tue Nov 14 2023(Updated: )
> ### CVSS: `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:F/RL:O/RC:C` (3.5) ### Problem The login screen of the standalone install tool discloses the full path of the transient data directory (e.g. _/var/www/html/var/transient/_). This applies to composer-based scenarios only - “classic” non-composer installations are not affected. ### Solution Update to TYPO3 version 12.4.8 that fixes the problem described above. ### Credits Thanks to Markus Klein who reported and fixed the issue. ### References * [TYPO3-CORE-SA-2023-005](https://typo3.org/security/advisory/typo3-core-sa-2023-005)
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/typo3/cms-install | >=12.2.0<12.4.8 | 12.4.8 |
Typo3 Typo3 | >=12.2.0<12.4.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-47126 is medium with a CVSS score of 5.3.
The Information Disclosure vulnerability in Install Tool in typo3/cms-install allows an attacker to obtain the full path of the transient data directory, potentially aiding in further attacks.
TYPO3 versions between 12.2.0 and 12.4.8 are affected by CVE-2023-47126.
To fix CVE-2023-47126, upgrade TYPO3 to version 12.4.8 or apply the recommended remedy.
You can find more information about CVE-2023-47126 at the following references: [GitHub Advisory](https://github.com/TYPO3/typo3/security/advisories/GHSA-p2jh-95jg-2w55), [GitHub Commit](https://github.com/TYPO3/typo3/commit/1a735dac01ec7b337ed0d80c738caa8967dea423), [TYPO3 Advisory](https://typo3.org/security/advisory/typo3-core-sa-2023-005).