From 0fb2ad7104d3e99a2290d28271eac232a250ffd0 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 14 Apr 2025 16:06:23 +0000 Subject: [PATCH] Publish GHSA-h7wf-jg4f-x2wc --- .../GHSA-h7wf-jg4f-x2wc.json | 44 ++++++++++++++++--- 1 file changed, 37 insertions(+), 7 deletions(-) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-h7wf-jg4f-x2wc/GHSA-h7wf-jg4f-x2wc.json (51%) diff --git a/advisories/unreviewed/2022/05/GHSA-h7wf-jg4f-x2wc/GHSA-h7wf-jg4f-x2wc.json b/advisories/github-reviewed/2022/05/GHSA-h7wf-jg4f-x2wc/GHSA-h7wf-jg4f-x2wc.json similarity index 51% rename from advisories/unreviewed/2022/05/GHSA-h7wf-jg4f-x2wc/GHSA-h7wf-jg4f-x2wc.json rename to advisories/github-reviewed/2022/05/GHSA-h7wf-jg4f-x2wc/GHSA-h7wf-jg4f-x2wc.json index 4f724b99e11..89ef35ad6fb 100644 --- a/advisories/unreviewed/2022/05/GHSA-h7wf-jg4f-x2wc/GHSA-h7wf-jg4f-x2wc.json +++ b/advisories/github-reviewed/2022/05/GHSA-h7wf-jg4f-x2wc/GHSA-h7wf-jg4f-x2wc.json @@ -1,22 +1,52 @@ { "schema_version": "1.4.0", "id": "GHSA-h7wf-jg4f-x2wc", - "modified": "2025-04-12T12:34:25Z", + "modified": "2025-04-14T16:04:38Z", "published": "2022-05-17T04:42:47Z", "aliases": [ "CVE-2014-3945" ], + "summary": "TYPO3 vulnerable to authentication bypass via leveraging knowledge of password hash", "details": "The Authentication component in TYPO3 before 6.2, when salting for password hashing is disabled, does not require knowledge of the cleartext password if the password hash is known, which allows remote attackers to bypass authentication and gain access to the backend by leveraging knowledge of a password hash.", - "severity": [], - "affected": [], + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "6.2.0" + } + ] + } + ] + } + ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-3945" }, + { + "type": "PACKAGE", + "url": "https://github.com/TYPO3/typo3" + }, { "type": "WEB", - "url": "http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2014-001" + "url": "https://typo3.org/security/advisory/typo3-core-sa-2014-001" }, { "type": "WEB", @@ -31,9 +61,9 @@ "cwe_ids": [ "CWE-287" ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2025-04-14T16:04:38Z", "nvd_published_at": "2014-06-03T14:55:00Z" } } \ No newline at end of file