Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-347x-877p-hcwx

Опубликовано: 13 мая 2020
Источник: github
Github: Прошло ревью
CVSS3: 3.7

Описание

Information Disclosure in Password Reset

In TYPO3 CMS 10.4.0 through 10.4.1, it has been discovered that time-based attacks can be used with the password reset functionality for backend users. This allows an attacker to mount user enumeration based on email addresses assigned to backend user accounts.

This has been fixed in 10.4.2.

References

Пакеты

Наименование

typo3/cms-core

composer
Затронутые версииВерсия исправления

>= 10.0.0, < 10.4.2

10.4.2

Наименование

typo3/cms

composer
Затронутые версииВерсия исправления

>= 10.0.0, < 10.4.2

10.4.2

EPSS

Процентиль: 52%
0.00292
Низкий

3.7 Low

CVSS3

Дефекты

CWE-203
CWE-204

Связанные уязвимости

CVSS3: 3.7
nvd
больше 5 лет назад

In TYPO3 CMS versions 10.4.0 and 10.4.1, it has been discovered that time-based attacks can be used with the password reset functionality for backend users. This allows an attacker to mount user enumeration based on email addresses assigned to backend user accounts. This has been fixed in 10.4.2.

EPSS

Процентиль: 52%
0.00292
Низкий

3.7 Low

CVSS3

Дефекты

CWE-203
CWE-204