CVE-2022-23501
TYPO3 CMS vulnerable to Weak Authentication in Frontend Login
5.9
MEDIUM
CVSS 3.1
EPSS 0.48%
描述
TYPO3 is an open source PHP based web content management system. In versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 TYPO3 is vulnerable to Improper Authentication. Restricting frontend login to specific users, organized in different storage folders (partitions), can be bypassed. A potential attacker might use this ambiguity in usernames to get access to a different account - however, credentials must be known to the adversary. This issue is patched in versions 8.7.49 ELTS, 9.5.38 ELTS, 10.4.33, 11.5.20, 12.1.1.
如何修補 CVE-2022-23501
要修補 CVE-2022-23501,請將受影響套件升級到下列已修補版本。
- —升級至 8.7.49 或更新版本
- —升級至 10.4.33 或更新版本
- —升級至 8.7.49 或更新版本
CVE-2022-23501 正在被利用嗎?
低 — EPSS 為 0.5%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 8.7.49, >= 9.0.0, < 9.5.38, >= 10.0.0, < 10.4.33, >= 11.0.0, < 11.5.20, >= 12.0.0, < 12.1.1
- >= 10.0.0, < 10.4.33
- from 0, < 8.7.49
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.9 | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N |