TYPO3 10.4.32

Release Notes

Version 10.4.32

Stay secure and up-to-date with TYPO3 ELTS!

The TYPO3 CMS community supported from 2020-04-21 until 2023-04-30.
Extend your support now until 2026-04-30 to get access to the latest security and compatibility updates for this version.

Learn more about TYPO3 ELTS Browse the TYPO3 ELTS Portal

Release Notes for TYPO3 CMS 10.4.32

This document contains information about TYPO3 CMS 10.4.32 which was released on 13.09.2022.

Get TYPO3 10.4.32 now

Checksums of TYPO3 10.4.32

SHA256

abfdeaa8119746a84898a3d4d7e368a6277b5a916c0a2e5dc7bd053282c0573b typo3_src-10.4.32.tar.gz
2ecefda4807c3c42805b92064b32e588dcab1acb07ccda295421028913c26fda typo3_src-10.4.32.zip

SHA1

2ba858fb88cc148150815281a8bff5470f24473e typo3_src-10.4.32.tar.gz
ab77e895347be702cf69f424de959ff84a406a0d typo3_src-10.4.32.zip

MD5

14d10a76ab0fdb340d06a03fc4c291ad typo3_src-10.4.32.tar.gz
ffa0eb2816152d71dadbb6d051fc7083 typo3_src-10.4.32.zip

Package Signatures

TYPO3 Release Packages (the downloadable tarballs and zip files) as well as Git tags are signed using PGP signatures during the automated release process. Besides that, MD5 and SHA2-256 hashes are being generated for these files. Find more details on verifying signatures and hashes in the infrastructure guide.

Download GPG signed release README.md file

Example of verifying integrity of tar.gz package of current release:

wget --content-disposition https://get.typo3.org/10.4.32/tar.gz
wget --content-disposition https://get.typo3.org/10.4.32/tar.gz.sig
gpg --verify typo3_src-10.4.32.tar.gz.sig typo3_src-10.4.32.tar.gz

Upgrading

The usual upgrading procedure applies. No database updates are necessary. It might be required to clear all caches; the "important actions" section in the TYPO3 Install Tool offers the accordant possibility to do so.

Changes

Here is a list of what was fixed since 10.4.31:

  • 2022-09-13 1a3a7c13e8 [RELEASE] Release of TYPO3 10.4.32 (thanks to Oliver Hader)
  • 2022-09-13 f421d079af [SECURITY] Upgrade to typo3/html-sanitizer v2.0.16 (thanks to Oliver Hader)
  • 2022-09-13 ffb89e0792 [SECURITY] Encode child node variables in f:asset.css view helper (thanks to Oliver Hader)
  • 2022-09-13 b880477e16 [SECURITY] Mitigate cross-site-scripting in FileDumpController (thanks to Oliver Hader)
  • 2022-09-13 dffc750623 [SECURITY] Respect expiration time of password reset token (thanks to Torben Hansen)
  • 2022-09-13 8428583541 [SECURITY] Mitigate timing discrepancies during user authentication (thanks to Oliver Hader)
  • 2022-09-07 801003d15a [TASK] Use current git repository links (thanks to Stephan Großberndt)
  • 2022-09-05 2e67318de1 [TASK] Update settings snippet: use default values everywhere (thanks to Josef Glatz)
  • 2022-08-16 a4f1a6f3a6 [BUGFIX] Avoid open_basedir errors when referencing absolute URLs (thanks to Benni Mack)
  • 2022-08-12 d506431265 Revert "[BUGFIX] Abort commit if commit message does not fulfill all requirements" (thanks to Christian Kuhn)
  • 2022-08-12 fa8c0cc5ab [BUGFIX] Disable pagetree drag and drop for touch inputs (thanks to Benjamin Kott)
  • 2022-08-11 75aee8ac75 [BUGFIX] Allow non-valid absolute paths for createVersionNumberFileName (thanks to Benni Mack)
  • 2022-08-07 8c724b776e [BUGFIX] Abort commit if commit message does not fulfill all requirements (thanks to Simon Schaufelberger)
  • 2022-08-05 6739febe2d [BUGFIX] Use sanitized filename as source identifier when replacing an image (thanks to Simon Schaufelberger)
  • 2022-08-05 4408fa2f03 [TASK] Remove docker-compose v1 enforce check from runTests.sh (thanks to Stefan Bürk)
  • 2022-08-01 24fe7d5aa6 [BUGFIX] Add sys_language_uid for PageSlugCandidateProvider (thanks to Benni Mack)
  • 2022-07-30 780ee8b30e [BUGFIX] Prevent duplicate page tree items when entry points intersect (thanks to Nikita Hovratov)
  • 2022-07-30 80ecc2c7cd [BUGFIX] Ensure deterministic sorting in PageTreeRepository (thanks to Stefan Bürk)
  • 2022-07-29 adab573eb7 [BUGFIX] Raise minimum version of symfony/mime to 4.4.16 / 5.1.8 (thanks to Oliver Hader)
  • 2022-07-28 85ee6b16cd [TASK] Add functional tests to test the caching behavior of ext:form (thanks to Ralf Zimmermann)
  • 2022-07-26 8bcc8d0db4 [TASK] Raise typo3/testing-framework (thanks to Christian Kuhn)
  • 2022-07-24 7a1038d4f7 [TASK] Unpin CI image docker:20.10.14-dind (thanks to Christian Kuhn)
  • 2022-07-15 03bc23b995 [BUGFIX] Allow changing FF sections in new version overlays (thanks to Christian Kuhn)
  • 2022-07-14 76e90dd3b3 [DOCS] Remove References to "Inside TYPO3" (thanks to linawolf)
  • 2022-07-14 c102739e0f [BUGFIX] Skip resolving backpath for already absolute paths (thanks to Oliver Bartsch)
  • 2022-07-13 5942e47ec4 [BUGFIX] Enhance annotation integrity test script (thanks to Stefan Bürk)
  • 2022-07-12 d7a3720bbb [TASK] Set TYPO3 version to 10.4.32-dev (thanks to Oliver Hader)