VDB
Sign up
MEDIUM4.8

GHSA-3276-p9f2-8q89

TYPO3 is vulnerable to insecure randomness during hash generation in forgot password function

Quick fix

GHSA-3276-p9f2-8q89 — typo3/cms-frontend: upgrade to the fixed version with the command below.

composer require typo3/cms-frontend:^4.3.4

Details

TYPO3 before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness during generation of a hash with the "forgot password" function.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/typo3/cms-frontend
Introduced in: 0Fixed in: 4.3.4
Fixcomposer require typo3/cms-frontend:^4.3.4
Packagist/typo3/cms-frontend
Introduced in: 4.4.0Fixed in: 4.4.1
Fixcomposer require typo3/cms-frontend:^4.4.1

References