CVE-2022-31047
Insertion of Sensitive Information into Log File in typo3/cms-core
5.3
MEDIUM
CVSS 3.1
EPSS 1.0%
Description
TYPO3 is an open source web content management system. Prior to versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, and 11.5.11, system internal credentials or keys (e.g. database credentials) can be logged as plaintext in exception handlers, when logging the complete exception stack trace. TYPO3 versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, 11.5.11 contain a fix for the problem.
How to fix CVE-2022-31047
To remediate CVE-2022-31047, upgrade the affected package to a fixed version below.
- —upgrade to 7.6.57 or later
- —upgrade to 10.4.29 or later
- —upgrade to 7.6.57 or later
Is CVE-2022-31047 being exploited?
Low — EPSS is 1.0%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- >= 7.0.0, < 7.6.57, >= 8.0.0, < 8.7.47, >= 9.0.0, < 9.5.35, >= 10.0.0, < 10.4.29, >= 11.0.0, < 11.5.11
- >= 10.0.0, < 10.4.29
- >= 7.0.0, < 7.6.57
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |