Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-jfp7-79g7-89rf: TYPO3 CMS vulnerable to Weak Authentication in Frontend Login

Problem

Restricting frontend login to specific users, organized in different storage folders (partitions), can be bypassed. A potential attacker might use this ambiguity in usernames to get access to a different account - however, credentials must be known to the adversary.

Solution

Update to TYPO3 versions 8.7.49 ELTS, 9.5.38 ELTS, 10.4.33, 11.5.20, 12.1.1 that fix the problem described above.

References

ghsa
#git#auth
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2022-23501

TYPO3 CMS vulnerable to Weak Authentication in Frontend Login

Moderate severity GitHub Reviewed Published Dec 13, 2022 in TYPO3/typo3 • Updated Dec 13, 2022

Package

composer typo3/cms-core (Composer)

Affected versions

< 8.7.49

>= 9.0.0, < 9.5.38

>= 10.0.0, < 10.4.33

>= 11.0.0, < 11.5.20

>= 12.0.0, < 12.1.1

Patched versions

8.7.49

9.5.38

10.4.33

11.5.20

12.1.1

Description

Severity

CVSS base metrics

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N

Weaknesses

GHSA ID

GHSA-jfp7-79g7-89rf

Source code

Related news

CVE-2022-23501: Weak Authentication in Frontend Login

TYPO3 is an open source PHP based web content management system. In versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 TYPO3 is vulnerable to Improper Authentication. Restricting frontend login to specific users, organized in different storage folders (partitions), can be bypassed. A potential attacker might use this ambiguity in usernames to get access to a different account - however, credentials must be known to the adversary. This issue is patched in versions 8.7.49 ELTS, 9.5.38 ELTS, 10.4.33, 11.5.20, 12.1.1.