The default configuration in the Dynamic Content Elements (dce) extension before 0.11.5 for TYPO3 allows remote attackers to obtain sensitive installation environment information by reading the update check request.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5281 | The default configuration in the Dynamic Content Elements (dce) extension before 0.11.5 for TYPO3 allows remote attackers to obtain sensitive installation environment information by reading the update check request. |
Github GHSA |
GHSA-v4vm-gj2x-6qhm | DCE extension for Typo3 Discloses Environment Information |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T13:18:48.304Z
Reserved: 2014-10-18T00:00:00
Link: CVE-2014-8328
No data.
Status : Modified
Published: 2020-02-03T14:15:10.553
Modified: 2024-11-21T02:18:52.893
Link: CVE-2014-8328
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA