| Vulnerability Name: | CVE-2014-3946 (CCN-93463) | ||||||||||||
| Assigned: | 2014-05-22 | ||||||||||||
| Published: | 2014-05-22 | ||||||||||||
| Updated: | 2014-06-04 | ||||||||||||
| Summary: | The query caching functionality in the Extbase Framework component in TYPO3 6.2.0 before 6.2.3 does not properly validate group permissions, which allows remote authenticated users to read arbitrary queries via unspecified vectors. | ||||||||||||
| CVSS v3 Severity: | 3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N)
| ||||||||||||
| CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||
| Vulnerability Type: | CWE-200 | ||||||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2014-3946 Source: CCN Type: TYPO3-CORE-SA-2014-001 Multiple Vulnerabilities in TYPO3 CMS Source: CONFIRM Type: Vendor Advisory http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2014-001/ Source: DEBIAN Type: UNKNOWN DSA-2942 Source: MLIST Type: UNKNOWN [oss-security] 20140603 Re: CVE ID request: typo3 Source: CCN Type: BID-67624 TYPO3 Extbase Framework Information Disclosure Vulnerability Source: XF Type: UNKNOWN typo3-extbase-info-disclosure(93463) | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| Oval Definitions | |||||||||||||
| |||||||||||||
| BACK | |||||||||||||