CVE-2014-3945
N/A
N/A
Summary
The Authentication component in TYPO3 before 6.2, when salting for password hashing is disabled, does not require knowledge of the cleartext password if the password hash is known, which allows remote attackers to bypass authentication and gain access to the backend by leveraging knowledge of a password hash.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.debian.org/security/2014/dsa-2942
- http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2014-001/
- http://www.openwall.com/lists/oss-security/2014/06/03/2
References
- http://www.debian.org/security/2014/dsa-2942
- http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2014-001/
- http://www.openwall.com/lists/oss-security/2014/06/03/2
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.