CVE-2009-3635: Medium severity typo3 vulnerability
The Install Tool subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attackers to gain access by using only the password's md5 hash as a credential.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3635?
CVE-2009-3635 is considered a high severity vulnerability due to the potential for unauthorized remote access using only an MD5 hash.
How do I fix CVE-2009-3635?
To fix CVE-2009-3635, upgrade to TYPO3 version 4.1.13, 4.2.10, or 4.3beta2 or later versions.
What versions of TYPO3 are affected by CVE-2009-3635?
CVE-2009-3635 affects TYPO3 versions 4.0.13 and earlier, all versions of 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2.
What does CVE-2009-3635 exploit?
CVE-2009-3635 exploits a flaw in the Install Tool subcomponent that allows attackers to authenticate using only the MD5 hash of a password.
Is there a workaround for CVE-2009-3635?
While upgrading is the recommended fix for CVE-2009-3635, disabling remote access to the Install Tool can serve as a temporary workaround.