CVE-2010-3670: Weak Encryption
Published Nov 5, 2019
·Updated
TYPO3 before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness during generation of a hash with the "forgot password" function.
Affected Software
5 affected componentsFixes available
composer/typo3/cms-frontend>=4.4.0<4.4.1
4.4.1
composer/typo3/cms-frontend<4.3.4
4.3.4
debian/typo3-src
Typo3 TYPO3>=4.4.0<4.4.1
Typo3 TYPO3<4.3.4
Event History
Nov 5, 2019
CVE Published
via MITRE·07:10 PM
Data Sourced
via MITRE·07:10 PM
Description
Apr 21, 2022
Advisory Published
via GitHub·01:57 AM
Frequently Asked Questions
1
What is the vulnerability ID for this TYPO3 issue?
The vulnerability ID for this TYPO3 issue is CVE-2010-3670.
2
What is the severity of CVE-2010-3670?
The severity of CVE-2010-3670 is medium.
3
What is the description of CVE-2010-3670?
CVE-2010-3670 is a vulnerability in TYPO3 before 4.3.4 and 4.4.x before 4.4.1 that contains insecure randomness during generation of a hash with the "forgot password" function.
4
What is the affected software for CVE-2010-3670?
The affected software for CVE-2010-3670 is TYPO3 versions up to 4.3.4 and TYPO3 versions up to 4.4.1.
5
Where can I find more information about CVE-2010-3670?
You can find more information about CVE-2010-3670 on the Debian Security Tracker and TYPO3 security advisory websites.