[TYPO3-core] Issue #26876 is public...

Björn Pedersen pedersen at frm2.tum.de
Thu Aug 4 10:30:08 CEST 2011


Am 04.08.2011 10:03, schrieb Steffen Müller:
> Hi,
> 
> the bugreport itself is read protected:
> http://forge.typo3.org/issues/26876
> 
> But since the chageset was merged to master, git log reveals
> "Unprivileged backend user can read arbitrarily from database"
> 
> The changeset is also public in gerrit:
> https://review.typo3.org/#change,4056
> 
> Question is: Is it critical and will a new release follow?
> 
Hi,

This is just a follow-up for legacy static TS files. The main file was
fixed in the latest release already. The criticallity depend on the
trust in your BE users.

Björn



More information about the TYPO3-team-core mailing list