Описание
TYPO3 Brute Force Protection Bypass in backend login
The backend login has a basic brute force protection implementation which pauses for 5 seconds if wrong credentials are given. This pause however could be bypassed by forging a special request, making brute force attacks on backend editor credentials more feasible.
Ссылки
- https://github.com/TYPO3/typo3/commit/0b67290bbd941c07b0101bbfd6c7aadcbb93c75c
- https://github.com/TYPO3/typo3/commit/0f3fb37674688aba5a44ca6f5df7f8a327a5b5f6
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/2015-07-01-5.yaml
- https://typo3.org/security/advisory/typo3-core-sa-2015-006
- https://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2015-006
Пакеты
Наименование
typo3/cms
composer
Затронутые версииВерсия исправления
>= 6.2.0, < 6.2.14
6.2.14
Наименование
typo3/cms
composer
Затронутые версииВерсия исправления
>= 7.0.0, < 7.3.1
7.3.1
6.5 Medium
CVSS3
Дефекты
CWE-20
6.5 Medium
CVSS3
Дефекты
CWE-20