CVE-2022-31047

MEDIUM

TYPO3 <7.6.57 ELTS, <8.7.47 ELTS, <9.5.34 ELTS, <10.4.29, <11.5.11 ...

Title source: llm
STIX 2.1

Description

TYPO3 is an open source web content management system. Prior to versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, and 11.5.11, system internal credentials or keys (e.g. database credentials) can be logged as plaintext in exception handlers, when logging the complete exception stack trace. TYPO3 versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, 11.5.11 contain a fix for the problem.

References (3)

Core 3

Scores

CVSS v3 5.3
EPSS 0.0039
EPSS Percentile 60.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-532 CWE-209
Status published
Products (4)
typo3/cms 10.0.0 - 10.4.29Packagist
typo3/cms-core 7.0.0 - 7.6.57Packagist
typo3/typo3 10.0.0 - 10.4.29
typo3/typo3 7.0.0 - 7.6.57
Published Jun 14, 2022
Tracked Since Feb 18, 2026