VDB
Sign up
CRITICAL9.8

GHSA-79gv-5cgx-x6rx

Typo3 Authentication Bypass

Quick fix

GHSA-79gv-5cgx-x6rx — typo3/cms: upgrade to the fixed version with the command below.

composer require typo3/cms:^4.3.12

Details

TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to bypass authentication mechanisms in the backend through a crafted request.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/typo3/cms
Introduced in: 0Fixed in: 4.3.12
Fixcomposer require typo3/cms:^4.3.12
Packagist/typo3/cms
Introduced in: 4.4.0Fixed in: 4.4.9
Fixcomposer require typo3/cms:^4.4.9
Packagist/typo3/cms
Introduced in: 4.5.0Fixed in: 4.5.4
Fixcomposer require typo3/cms:^4.5.4

References