Information Disclosure in typo3/cms-install tool
Description
Published by the National Vulnerability Database
Nov 14, 2023
Published to the GitHub Advisory Database
Nov 14, 2023
Reviewed
Nov 14, 2023
Last updated
Nov 14, 2023
Problem
The login screen of the standalone install tool discloses the full path of the transient data directory (e.g. /var/www/html/var/transient/). This applies to composer-based scenarios only - “classic” non-composer installations are not affected.
Solution
Update to TYPO3 version 12.4.8 that fixes the problem described above.
Credits
Thanks to Markus Klein who reported and fixed the issue.
References
References