[SECURITY] Information Disclosure in the Configuration Module
authorMario Rimann <mario.rimann@typo3.org>
Wed, 15 Aug 2012 10:21:16 +0000 (12:21 +0200)
committerOliver Hader <oliver.hader@typo3.org>
Wed, 15 Aug 2012 10:21:23 +0000 (12:21 +0200)
commit788d9c19930a3d8f638e54b2bdf0ba67ecd82fbf
tree493506903e3525e6b9c6feec4a6584938fe838a2
parent05d760ac56d7295b8f42c766c90d2f12d50dab37
[SECURITY] Information Disclosure in the Configuration Module

The configuration module showed the encryption key as plaintext.
For this view, the encryption key is masked and it's length is
shown instead, e.g. "***** (length: 96 characters)"

Change-Id: I16145e76a60d15d8e9575ef0cc5cf3cd54b1b6b1
Fixes: #39345
Releases: 6.0, 4.7, 4.6, 4.5
Security-Commit: c9b4932c07d1b95c47e5c184b74c2d3493db3b06
Security-Bulletin: TYPO3-CORE-SA-2012-004
Reviewed-on: http://review.typo3.org/13768
Reviewed-by: Oliver Hader
Tested-by: Oliver Hader
typo3/sysext/lowlevel/config/index.php