Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-38r2-5695-334w: TYPO3 Backend Forms vulnerable to Information Disclosure of Hashed Passwords

Problem

Password hashes were being reflected in the editing forms of the TYPO3 backend user interface. This allowed attackers to crack the plaintext password using brute force techniques. Exploiting this vulnerability requires a valid backend user account.

Solution

Update to TYPO3 versions 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, 13.0.1 that fix the problem described.

Credits

Thanks to the TYPO3 framework merger Christian Kuhn and external security researchers Maximilian Beckmann, Klaus-Günther Schmidt who reported this issue, and TYPO3 security team member Oliver Hader who fixed the issue.

References

ghsa
#vulnerability#git
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2024-25118

TYPO3 Backend Forms vulnerable to Information Disclosure of Hashed Passwords

Moderate severity GitHub Reviewed Published Feb 13, 2024 in TYPO3/typo3

Package

composer typo3/cms-core (Composer)

Affected versions

>= 8.0.0, <= 8.7.56

>= 9.0.0, <= 9.5.45

>= 10.0.0, <= 10.4.42

>= 11.0.0, <= 11.5.34

>= 12.0.0, <= 12.4.10

= 13.0.0

Patched versions

8.7.57

9.5.46

10.4.43

11.5.35

12.4.11

13.0.1

Problem

Password hashes were being reflected in the editing forms of the TYPO3 backend user interface. This allowed attackers to crack the plaintext password using brute force techniques. Exploiting this vulnerability requires a valid backend user account.

Solution

Update to TYPO3 versions 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, 13.0.1 that fix the problem described.

Credits

Thanks to the TYPO3 framework merger Christian Kuhn and external security researchers Maximilian Beckmann, Klaus-Günther Schmidt who reported this issue, and TYPO3 security team member Oliver Hader who fixed the issue.

References

  • TYPO3-CORE-SA-2024-003

References

  • GHSA-38r2-5695-334w
  • TYPO3/typo3@1186b2f
  • TYPO3/typo3@c7a135c
  • TYPO3/typo3@cafc5af
  • https://typo3.org/security/advisory/typo3-core-sa-2024-003

Published to the GitHub Advisory Database

Feb 13, 2024

ghsa: Latest News

GHSA-x7m9-mv49-fv73: Vaultwarden vulnerable to user impersonation