Commit baa8089
committed
[SECURITY] Avoid logging install tool password on hashing issue
This change avoids logging the submitted plain-text install tool
password in case the server-side hash was invalid.
Resolves: #105685
Releases: main, 13.4
Change-Id: I0b83e672d612a14442d5023361a96bd863947492
Security-Bulletin: TYPO3-CORE-SA-2025-001
Security-References: CVE-2024-55891
Reviewed-on: https://review.typo3.org/c/Packages/TYPO3.CMS/+/87742
Reviewed-by: Oliver Hader <oliver.hader@typo3.org>
Tested-by: Oliver Hader <oliver.hader@typo3.org>1 parent cf8a6bc commit baa8089
1 file changed
+2
-2
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
70 | 70 | | |
71 | 71 | | |
72 | 72 | | |
73 | | - | |
| 73 | + | |
74 | 74 | | |
75 | | - | |
| 75 | + | |
76 | 76 | | |
77 | 77 | | |
78 | 78 | | |
| |||
0 commit comments