Information Disclosure in User Authentication

Categories: Development Created by Oliver Hader
It has been discovered, that TYPO3 CMS is susceptible to information disclosure.
  • Component Type: TYPO3 CMS
  • Vulnerable subcomponent: User Authentication (ext:core)
  • Release Date: May 7, 2019
  • Vulnerability Type: Information Disclosure
  • Affected Versions: 9.0.0-9.5.5
  • Severity: Medium
  • Suggested CVSS v3.0: AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
  • CVE: not assigned yet

Problem Description

It has been discovered that login failures have been logged on the default stream with log level "warning" including plain-text user credentials.

Solution

Update to TYPO3 version 9.5.6 that fixes the problem described. The according log level has been changed to "debug" which needs to be enabled explicitly.

Credits

Thanks to Helmut Hummel who reported and fixed this issue.

General Advice

Follow the recommendations that are given in the TYPO3 Security Guide. Please subscribe to the typo3-announce mailing list.

General Note

All security related code changes are tagged so that you can easily look them up in our review system.