CVE-2022-23501
MEDIUM5.9EPSS 0.19%TYPO3 CMS vulnerable to Weak Authentication in Frontend Login
發布日:2022/12/13修改日:2023/12/6
描述
### Problem Restricting frontend login to specific users, organized in different storage folders (partitions), can be bypassed. A potential attacker might use this ambiguity in usernames to get access to a different account - however, credentials must be known to the adversary. ### Solution Update to TYPO3 versions 8.7.49 ELTS, 9.5.38 ELTS, 10.4.33, 11.5.20, 12.1.1 that fix the problem described above. ### References * [TYPO3-CORE-SA-2022-013](https://typo3.org/security/advisory/typo3-core-sa-2022-013)
受影響套件(3)
- Bitnami/typo3from 0, < 8.7.49, >= 9.0.0, < 9.5.38, >= 10.0.0, < 10.4.33, >= 11.0.0, < 11.5.20, >= 12.0.0, < 12.1.1
- Packagist/typo3/cms>= 10.0.0, < 10.4.33
- Packagist/typo3/cms-corefrom 0, < 8.7.49
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.9 | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N |
參考連結(7)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2022-23501
- PATCHhttps://github.com/TYPO3/typo3
- WEBhttps://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2022-23501.yaml
- WEBhttps://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/CVE-2022-23501.yaml
- WEBhttps://github.com/TYPO3/typo3/commit/28be9cdb3fed02ce4cfc6fa2d39f7d8e2266eced
- WEBhttps://github.com/TYPO3/typo3/security/advisories/GHSA-jfp7-79g7-89rf
- WEBhttps://typo3.org/security/advisory/typo3-core-sa-2022-013