CVE-2014-3945: Medium severity Typo3 TYPO3 vulnerability
The Authentication component in TYPO3 before 6.2, when salting for password hashing is disabled, does not require knowledge of the cleartext password if the password hash is known, which allows remote attackers to bypass authentication and gain access to the backend by leveraging knowledge of a password hash.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3945?
CVE-2014-3945 has a high severity rating due to its potential to allow unauthorized access to the backend of TYPO3 systems.
How do I fix CVE-2014-3945?
To fix CVE-2014-3945, upgrade TYPO3 to version 6.2 or later, where salting for password hashing is enabled by default.
When was CVE-2014-3945 disclosed?
CVE-2014-3945 was disclosed in June 2014 as part of a security bulletin from TYPO3.
Which versions of TYPO3 are affected by CVE-2014-3945?
CVE-2014-3945 affects TYPO3 versions before 6.2, specifically 6.1.9 and earlier.
What impact does CVE-2014-3945 have on TYPO3 applications?
CVE-2014-3945 allows attackers to bypass authentication and gain unauthorized access to the TYPO3 backend.