{"id":"GHSA-38x7-cc6w-j27q","summary":"TYPO3 Information Disclosure via Exception Handling/Logger","details":"### Problem\nIt has been discovered that the install tool password has been logged as plaintext in case the password hashing mechanism used for the password was incorrect.\n\n### Solution\nUpdate to TYPO3 versions 13.4.3 LTS that fixes the problem described.\n\n### Credits\nThanks to TYPO3 core & security team member Oliver Hader who reported and fixed the issue.\n\n### References\n* [TYPO3-CORE-SA-2025-001](https://typo3.org/security/advisory/typo3-core-sa-2025-001)\n","aliases":["CVE-2024-55891"],"modified":"2025-01-14T22:21:48.236473Z","published":"2025-01-14T15:23:41Z","database_specific":{"nvd_published_at":"2025-01-14T20:15:28Z","cwe_ids":["CWE-532"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2025-01-14T15:23:41Z"},"references":[{"type":"WEB","url":"https://github.com/TYPO3/typo3/security/advisories/GHSA-38x7-cc6w-j27q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-55891"},{"type":"WEB","url":"https://github.com/TYPO3-CMS/install/commit/baa8089b1baf5552fab213a5761081608b0afc51"},{"type":"PACKAGE","url":"https://github.com/TYPO3-CMS/install"},{"type":"WEB","url":"https://typo3.org/security/advisory/typo3-core-sa-2025-001"}],"affected":[{"package":{"name":"typo3/cms-install","ecosystem":"Packagist","purl":"pkg:composer/typo3/cms-install"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13.4.2"},{"fixed":"13.4.3"}]}],"versions":["13.4.2","v13.4.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/01/GHSA-38x7-cc6w-j27q/GHSA-38x7-cc6w-j27q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}