TYPO3-PSA-2019-006: Security Misconfiguration since TYPO3 9.4.0
It has been discovered that TYPO3 is susceptible to security misconfiguration.
Read moreTYPO3-PSA-2019-005: Cross-Site Scripting in Bootstrap CSS toolkit before 3.4.1 and 4.3.0
It has been discovered that 3rd party library Bootstrap CSS toolkit bundled with TYPO3 is vulnerable to cross-site scripting through prototype pollution.
TYPO3-PSA-2019-004: Cross-Site Scripting in jQuery before 3.4.0
It has been discovered that 3rd party library jQuery bundled with TYPO3 is vulnerable to cross-site scripting through prototype pollution.
TYPO3-CORE-SA-2019-013: Cross-Site Scripting in Fluid Engine
It has been discovered, that TYPO3 CMS is vulnerable to cross-site scripting.
TYPO3-CORE-SA-2019-012: Possible Arbitrary Code Execution in Image Processing
It has been discovered, that TYPO3 CMS is vulnerable to arbitrary code execution.
TYPO3-CORE-SA-2019-011: Security Misconfiguration in User Session Handling
It has been discovered, that TYPO3 CMS is susceptible to security misconfiguration.
TYPO3-CORE-SA-2019-010: Information Disclosure in User Authentication
It has been discovered, that TYPO3 CMS is susceptible to information disclosure.
TYPO3-CORE-SA-2019-009: Information Disclosure in Page Tree
It has been discovered, that TYPO3 CMS is susceptible to information disclosure.
April 2019: Developer Appreciation Day (DAD)
As always, a new month starts off with Developer Appreciation Day (DAD): We‘d like to tip our hats to the devoted TYPO3 developers who contributed to the TYPO3 project during April. Thanks a lot, everyone! Find the contributor’s names and some truly impressive numbers in our recent article.
Results of the TYPO3 Association Elections 2019
The TYPO3 Association (T3A) communicates the results of the 2019 elections for the Board and Business Control Committee (BCC).