PT-2015-5567 · Typo3 · Rsaauth+1

Salvatore Bonaccorso

·

Publicado

2015-02-21

·

Atualizado

2016-11-30

·

CVE-2015-2047

CVSS v2.0

2.6

Baixa

VetorAV:N/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions TYPO3 versions 4.3.0 through 4.3.14 TYPO3 versions 4.4.0 through 4.4.15 TYPO3 versions 4.5.0 through 4.5.39 TYPO3 versions 4.6.0 through 4.6.18
Description The issue allows remote attackers to bypass authentication via a password that is casted to an empty value when the rsaauth extension is configured for the frontend.
Recommendations For versions 4.3.0 through 4.3.14, consider disabling the rsaauth extension for the frontend until a fix is available. For versions 4.4.0 through 4.4.15, consider disabling the rsaauth extension for the frontend until a fix is available. For versions 4.5.0 through 4.5.39, consider disabling the rsaauth extension for the frontend until a fix is available. For versions 4.6.0 through 4.6.18, consider disabling the rsaauth extension for the frontend until a fix is available.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-2047
DSA-3164-1

Produtos afetados

Typo3
Rsaauth