CVSS: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:F/RL:O/RC:C
(3.5)
Problem
The login screen of the standalone install tool discloses the full path of the transient data directory (e.g. /var/www/html/var/transient/). This applies to composer-based scenarios only - “classic” non-composer installations are not affected.
Solution
Update to TYPO3 version 12.4.8 that fixes the problem described above.
Credits
Thanks to Markus Klein who reported and fixed the issue.
References
Problem
The login screen of the standalone install tool discloses the full path of the transient data directory (e.g. /var/www/html/var/transient/). This applies to composer-based scenarios only - “classic” non-composer installations are not affected.
Solution
Update to TYPO3 version 12.4.8 that fixes the problem described above.
Credits
Thanks to Markus Klein who reported and fixed the issue.
References