Authentication Bypass in TYPO3 CMS
Moderate severity
GitHub Reviewed
Published
Jun 5, 2024
to the GitHub Advisory Database
•
Updated Jun 5, 2024
Package
Affected versions
>= 6.2.0, < 6.2.20
>= 7.6.0, < 7.6.5
>= 8.0.0, < 8.0.1
Patched versions
6.2.20
7.6.5
8.0.1
Description
Published to the GitHub Advisory Database
Jun 5, 2024
Reviewed
Jun 5, 2024
Last updated
Jun 5, 2024
The default authentication service misses to invalidate empty strings as password. Therefore it is possible to authenticate backend and frontend users without password set in the database.
Note: TYPO3 does not allow to create user accounts without a password. Your TYPO3 installation might only be affected if there is a third party component creating user accounts without password by directly manipulating the database.
References