{"id":"CVE-2014-8328","aliases":[],"url":"https://o3.security/vulnerability/CVE-2014-8328","summary":"DCE extension for Typo3 Discloses Environment Information","details":"The default configuration in the Dynamic Content Elements (dce) extension before 0.11.5 for TYPO3 allows remote attackers to obtain sensitive installation environment information by reading the update check request.","published":"2022-05-17T19:57:24Z","modified":"2023-11-08T03:57:45.721180Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"t3/dce","fixedVersion":"0.11.5"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-8328"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/97673"},{"type":"PACKAGE","url":"https://github.com/a-r-m-i-n/dce"},{"type":"WEB","url":"http://typo3.org/extensions/repository/view/dce"},{"type":"WEB","url":"http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2014-015"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T03:57:45.721180Z"}}