- Component Type: TYPO3 CMS
- Vulnerable subcomponent: User Authentication (ext:core)
- Release Date: May 7, 2019
- Vulnerability Type: Information Disclosure
- Affected Versions: 9.0.0-9.5.5
- Severity: Medium
- Suggested CVSS v3.0: AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
- CVE: not assigned yet
It has been discovered that login failures have been logged on the default stream with log level "warning" including plain-text user credentials.
Update to TYPO3 version 9.5.6 that fixes the problem described. The according log level has been changed to "debug" which needs to be enabled explicitly.
Thanks to Helmut Hummel who reported and fixed this issue.
All security related code changes are tagged so that you can easily look them up in our review system.