CVE-2014-3946
Typo3 Information Disclosure
EPSS 1.1%
描述
Failing to respect user groups of logged in users when caching queries, Extbase is susceptible to information disclosure. The query caching (introduced in Extbase 6.2) used to cache queries that query results for a specific user group were presented to a different group.
如何修補 CVE-2014-3946
要修補 CVE-2014-3946,請將受影響套件升級到下列已修補版本。
- Packagist/typo3/cms—升級至 6.2.3 或更新版本
CVE-2014-3946 正在被利用嗎?
低 — EPSS 為 1.1%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- >= 6.2.0, < 6.2.3