
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability (GHSA-m96r-7vqm-j95g) titled 'Information Disclosure in User Authentication' was discovered in TYPO3 CMS and disclosed on May 7, 2019. This security issue affected TYPO3 CMS versions 9.0.0 through 9.5.5. The vulnerability was classified as medium severity and involved the exposure of user credentials in system logs (TYPO3 Advisory).
The vulnerability occurred when login failures were logged on the default stream with log level 'warning', which inadvertently included plain-text user credentials. The suggested CVSS v3.0 score metrics are AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N, indicating a medium severity level (TYPO3 Advisory).
This vulnerability could lead to the exposure of user credentials through system logs, potentially compromising user account security. The impact was significant enough to warrant a security advisory, though it required specific conditions to be exploited (GitHub Advisory).
The vulnerability required local access to system logs and specific conditions to be exploited. The CVSS metrics indicate that exploitation needed network access (AV:N), high attack complexity (AC:H), low privileges (PR:L), and user interaction (UI:R) (TYPO3 Advisory).
The vulnerability was fixed in TYPO3 version 9.5.6. The fix involved changing the log level for failed login attempts from 'warning' to 'debug', which needs to be enabled explicitly. Users are advised to update to version 9.5.6 or later to address this security issue (TYPO3 Advisory).
The vulnerability was discovered and fixed by Helmut Hummel, who received credit for reporting and addressing the issue (TYPO3 Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."