MEDIUM4.8
GHSA-3276-p9f2-8q89
TYPO3 is vulnerable to insecure randomness during hash generation in forgot password function
Quick fix
GHSA-3276-p9f2-8q89 — typo3/cms-frontend: upgrade to the fixed version with the command below.
composer require typo3/cms-frontend:^4.3.4Details
TYPO3 before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness during generation of a hash with the "forgot password" function.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/typo3/cms-frontend
Introduced in:
0Fixed in: 4.3.4Fix
composer require typo3/cms-frontend:^4.3.4Packagist/typo3/cms-frontend
Introduced in:
4.4.0Fixed in: 4.4.1Fix
composer require typo3/cms-frontend:^4.4.1References
- https://nvd.nist.gov/vuln/detail/CVE-2010-3670[ADVISORY]
- https://github.com/TYPO3/typo3/commit/09ab77653161f23e266470a5984d4d5e64588355[WEB]
- https://github.com/TYPO3/typo3/commit/c03e944d200bf427bb18cad15f2ad36bc83061c9[WEB]
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=590719[WEB]
- https://github.com/TYPO3-CMS/frontend[PACKAGE]
- https://security-tracker.debian.org/tracker/CVE-2010-3670[WEB]
- https://typo3.org/security/advisory/typo3-sa-2010-012/#Insecure_Randomness[WEB]