VulnerabilityModified
CVE-2014-3946
The query caching functionality in the Extbase Framework component in TYPO3 6.2.0 before 6.2.3 does not properly validate group permissions, which allows remote authenticated users to read arbitrary queries via unspecified vectors.
MEDIUM 4.0EPSS 1.12%
Does this matter?
Lower severity and a low EPSS score (1.12%). Track it; it rarely justifies an emergency change on its own.
Description
The query caching functionality in the Extbase Framework component in TYPO3 6.2.0 before 6.2.3 does not properly validate group permissions, which allows remote authenticated users to read arbitrary queries via unspecified vectors.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
- EPSS
- 1.12% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- typo3/typo3
- Source
- cve@mitre.org
References
- http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2014-001/Vendor Advisory
- http://www.debian.org/security/2014/dsa-2942
- http://www.openwall.com/lists/oss-security/2014/06/03/2
- http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2014-001/Vendor Advisory
- http://www.debian.org/security/2014/dsa-2942
- http://www.openwall.com/lists/oss-security/2014/06/03/2
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.