Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jfp7-79g7-89rf

Опубликовано: 13 дек. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

TYPO3 CMS vulnerable to Weak Authentication in Frontend Login

Problem

Restricting frontend login to specific users, organized in different storage folders (partitions), can be bypassed. A potential attacker might use this ambiguity in usernames to get access to a different account - however, credentials must be known to the adversary.

Solution

Update to TYPO3 versions 8.7.49 ELTS, 9.5.38 ELTS, 10.4.33, 11.5.20, 12.1.1 that fix the problem described above.

References

Пакеты

Наименование

typo3/cms-core

composer
Затронутые версииВерсия исправления

< 8.7.49

8.7.49

Наименование

typo3/cms-core

composer
Затронутые версииВерсия исправления

>= 9.0.0, < 9.5.38

9.5.38

Наименование

typo3/cms-core

composer
Затронутые версииВерсия исправления

>= 10.0.0, < 10.4.33

10.4.33

Наименование

typo3/cms-core

composer
Затронутые версииВерсия исправления

>= 11.0.0, < 11.5.20

11.5.20

Наименование

typo3/cms-core

composer
Затронутые версииВерсия исправления

>= 12.0.0, < 12.1.1

12.1.1

Наименование

typo3/cms

composer
Затронутые версииВерсия исправления

>= 10.0.0, < 10.4.33

10.4.33

Наименование

typo3/cms

composer
Затронутые версииВерсия исправления

>= 11.0.0, < 11.5.20

11.5.20

Наименование

typo3/cms

composer
Затронутые версииВерсия исправления

>= 12.0.0, < 12.1.1

12.1.1

EPSS

Процентиль: 41%
0.00187
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-287
CWE-302

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 3 лет назад

TYPO3 is an open source PHP based web content management system. In versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 TYPO3 is vulnerable to Improper Authentication. Restricting frontend login to specific users, organized in different storage folders (partitions), can be bypassed. A potential attacker might use this ambiguity in usernames to get access to a different account - however, credentials must be known to the adversary. This issue is patched in versions 8.7.49 ELTS, 9.5.38 ELTS, 10.4.33, 11.5.20, 12.1.1.

CVSS3: 5.9
nvd
около 3 лет назад

TYPO3 is an open source PHP based web content management system. In versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 TYPO3 is vulnerable to Improper Authentication. Restricting frontend login to specific users, organized in different storage folders (partitions), can be bypassed. A potential attacker might use this ambiguity in usernames to get access to a different account - however, credentials must be known to the adversary. This issue is patched in versions 8.7.49 ELTS, 9.5.38 ELTS, 10.4.33, 11.5.20, 12.1.1.

EPSS

Процентиль: 41%
0.00187
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-287
CWE-302