Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h7wf-jg4f-x2wc

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.1

Описание

TYPO3 vulnerable to authentication bypass via leveraging knowledge of password hash

The Authentication component in TYPO3 before 6.2, when salting for password hashing is disabled, does not require knowledge of the cleartext password if the password hash is known, which allows remote attackers to bypass authentication and gain access to the backend by leveraging knowledge of a password hash.

Пакеты

Наименование

typo3/cms

composer
Затронутые версииВерсия исправления

< 6.2.0

6.2.0

EPSS

Процентиль: 42%
0.00198
Низкий

9.1 Critical

CVSS4

Дефекты

CWE-287

Связанные уязвимости

ubuntu
больше 11 лет назад

The Authentication component in TYPO3 before 6.2, when salting for password hashing is disabled, does not require knowledge of the cleartext password if the password hash is known, which allows remote attackers to bypass authentication and gain access to the backend by leveraging knowledge of a password hash.

nvd
больше 11 лет назад

The Authentication component in TYPO3 before 6.2, when salting for password hashing is disabled, does not require knowledge of the cleartext password if the password hash is known, which allows remote attackers to bypass authentication and gain access to the backend by leveraging knowledge of a password hash.

debian
больше 11 лет назад

The Authentication component in TYPO3 before 6.2, when salting for pas ...

EPSS

Процентиль: 42%
0.00198
Низкий

9.1 Critical

CVSS4

Дефекты

CWE-287