Information Disclosure in User Authentication
Package
Affected versions
>= 10.0.0, < 10.4.18
>= 11.0.0, < 11.3.1
>= 9.0.0, < 9.5.28
Patched versions
10.4.18
11.3.1
9.5.28
>= 7.0.0, < 7.6.52
>= 8.0.0, < 8.7.41
>= 9.0.0, < 9.5.28
>= 10.0.0, < 10.4.18
>= 11.0.0, < 11.3.1
7.6.52
8.7.41
9.5.28
10.4.18
11.3.1
Description
Published by the National Vulnerability Database
Jul 20, 2021
Reviewed
Jul 22, 2021
Published to the GitHub Advisory Database
Jul 26, 2021
Last updated
Feb 5, 2024
Problem
It has been discovered that user credentials have been logged as plaintext when explicitly using log level debug, which is not the default configuration.
Solution
Update to TYPO3 versions 7.6.52 ELTS, 8.7.41 ELTS, 9.5.28, 10.4.18, 11.3.1 that fix the problem described.
Credits
Thanks to Ingo Schmitt who reported this issue, and to TYPO3 core & security team member Benni Mack who fixed the issue.
References
References