TYPO3 9.5.23

Release Notes

Version 9.5.23

Stay secure and up-to-date with TYPO3 ELTS!

The TYPO3 CMS community supported from 2018-10-02 until 2021-09-30.
Extend your support now until 2024-09-30 to get access to the latest security and compatibility updates for this version.

Learn more about TYPO3 ELTS Browse the TYPO3 ELTS Portal

Release Notes for TYPO3 CMS 9.5.23

This document contains information about TYPO3 CMS 9.5.23 which was released on 17.11.2020.

Get TYPO3 9.5.23 now

Checksums of TYPO3 9.5.23

SHA256

6453a7290329ae0bd37a8d656d9834694577ceb40b3376343061937a1c4cf30f typo3_src-9.5.23.tar.gz
4b62423c250408be0032a65a134686fe24c5115d40832c0501b8f1e6e1e47cc7 typo3_src-9.5.23.zip

SHA1

5b8886acab0cd15e831df91f977a7a5f646d1524 typo3_src-9.5.23.tar.gz
171cb1cf83823028acc7e8ea2b08be3163ca6274 typo3_src-9.5.23.zip

MD5

a790aa128c8e44145b032f1322c58825 typo3_src-9.5.23.tar.gz
541deed0d192ec9cdc27f7e363279dee typo3_src-9.5.23.zip

Package Signatures

TYPO3 Release Packages (the downloadable tarballs and zip files) as well as Git tags are signed using PGP signatures during the automated release process. Besides that, MD5 and SHA2-256 hashes are being generated for these files. Find more details on verifying signatures and hashes in the infrastructure guide.

Download GPG signed release README.md file

Example of verifying integrity of tar.gz package of current release:

wget --content-disposition https://get.typo3.org/9.5.23/tar.gz
wget --content-disposition https://get.typo3.org/9.5.23/tar.gz.sig
gpg --verify typo3_src-9.5.23.tar.gz.sig typo3_src-9.5.23.tar.gz

Upgrading

The usual upgrading procedure applies. No database updates are necessary. It might be required to clear all caches; the "important actions" section in the TYPO3 Install Tool offers the accordant possibility to do so.

Changes

Here is a list of what was fixed since 9.5.22:

  • 2020-11-17 e444d4492e [RELEASE] Release of TYPO3 9.5.23 (thanks to Oliver Hader)
  • 2020-11-17 dc26a4ac1a [SECURITY] Protect persisted session IDs from being used directly (thanks to Oliver Hader)
  • 2020-11-17 0f6b7b799e [SECURITY] Encode passed arguments in Fluid view helpers (thanks to Oliver Hader)
  • 2020-11-17 c23113e1cf [SECURITY] Upgrade typo3fluid/fluid to v2.6.10 (thanks to Oliver Hader)
  • 2020-11-17 c3fef52209 [BUGFIX] Do not try to evaluate fe_groups for page overlays (thanks to Markus Klein)
  • 2020-11-17 a41f4cf931 [BUGFIX] Do not use AdminPanel reference in EXT:frontend code (thanks to Benni Mack)
  • 2020-11-16 71693dfa61 [TASK] Introduce resource Content-Security-Policy check (thanks to Oliver Hader)
  • 2020-11-16 f79c9685a7 [TASK] Introduce sudo mode for install tool accessed via backend (thanks to Oliver Hader)
  • 2020-11-16 f24c2e1d8a [BUGFIX] Show flag for language "All" in the Page module (thanks to Dmitry Dulepov)
  • 2020-11-13 59b9a1e776 [TASK] Streamline server response check (thanks to Oliver Hader)
  • 2020-11-12 d973386c83 [DOCS] Improve documentation for Fluid f:translate viewhelper (thanks to Peter Kraume)
  • 2020-11-12 4284c568b1 [BUGFIX] Do not consider empty files being an image or media file (thanks to Helmut Hummel)
  • 2020-11-12 319b24a3c9 [BUGFIX] Felogin allows redirect to any site (thanks to Markus Klein)
  • 2020-11-11 656b5eba09 [BUGFIX] Reintroduce the check on options.saveDocNew (thanks to Xavier Perseguers)
  • 2020-11-11 8c82cceb7a [FEATURE] Add options to locally test on composer min and max stages (thanks to Anja Leichsenring)
  • 2020-11-11 448edba0e6 [FEATURE] Allow more DBMS-Versions for local testing (thanks to Anja Leichsenring)
  • 2020-11-07 63ed9f2a53 [BUGFIX] Fix type error in TCA table wizard for null values (thanks to Daniel Siepmann)
  • 2020-11-07 9d124ea8b4 [TASK] Upgrade typo3/phar-stream-wrapper to v3.1.6 (thanks to Oliver Hader)
  • 2020-11-07 323bba659d [TASK] Enforce Composer 2 usage for TYPO3 development (thanks to Helmut Hummel)
  • 2020-11-04 0dd674fe31 [BUGFIX] Provide colPos for each cell in defLangBinding view (thanks to Oliver Bartsch)
  • 2020-10-31 981bdb4331 [BUGFIX] Apply fixes from newer php-cs-fixer (thanks to Andreas Fernandez)
  • 2020-10-30 ccdce8194d [TASK] Update build plans to support Composer 2 (thanks to Andreas Fernandez)
  • 2020-10-28 db54f9ff3d [DOCS] Update linkvalidator documentation: Administration (thanks to Sybille Peters)
  • 2020-10-27 abaf8c2454 [BUGFIX] Mark page for previewing when admin panel is active (thanks to Benni Mack)
  • 2020-10-27 7e5e89b8cd [DOCS] Update linkvalidator documentation Introduction (thanks to Sybille Peters)
  • 2020-10-22 5919fa96e9 [BUGFIX] Limit doctrine/dbal to 2.10.x or 2.11.2+ (thanks to Markus Klein)
  • 2020-10-22 62815611ba [BUGFIX] Fix PHP type error in f:form.select.optgroup view helper (thanks to Oliver Hader)
  • 2020-10-19 95ed3e3ccc [BUGFIX] Migrate the most accurate RealURL page path to page slugs (thanks to Mathias Brodala)
  • 2020-10-13 316ec30858 [BUGFIX] Quote double quotes in CSV integrity fix script (thanks to Christian Kuhn)
  • 2020-10-13 d22e99e88c [BUGFIX] Fix SQL error in backend user list on PostgreSQL (thanks to Stephan Großberndt)
  • 2020-10-12 60d5c9536e [BUGFIX] Fix type error in log upgrade wizard (thanks to Georg Großberger)
  • 2020-10-08 639109813f [BUGFIX] If is_regexp = 1 then source_path must wrap in # (thanks to Mohsin Khan)
  • 2020-10-08 5cec5264ea [BUGFIX] Use correct regular expression in FormDefinitionConversionService (thanks to Georg Ringer)
  • 2020-10-02 38e75d960d [TASK] Define callable controller actions (thanks to Oliver Hader)
  • 2020-09-29 505fe2d17e [TASK] Set TYPO3 version to 9.5.23-dev (thanks to Benni Mack)