CVE-2020-11063

Source
https://cve.org/CVERecord?id=CVE-2020-11063
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-11063.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-11063
Aliases
Published
2020-05-13T23:15:11.047Z
Modified
2026-07-08T05:59:57.614392256Z
Severity
  • 3.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

In TYPO3 CMS versions 10.4.0 and 10.4.1, it has been discovered that time-based attacks can be used with the password reset functionality for backend users. This allows an attacker to mount user enumeration based on email addresses assigned to backend user accounts. This has been fixed in 10.4.2.

Database specific
{
    "unresolved_ranges": [
        {
            "source": "CPE_STRING",
            "vendor_product": "typo3:typo3",
            "extracted_events": [
                {
                    "introduced": "10.4.0"
                },
                {
                    "last_affected": "10.4.0"
                },
                {
                    "introduced": "10.4.0"
                },
                {
                    "last_affected": "10.4.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:typo3:typo3:10.4.0:*:*:*:*:*:*:*"
            ]
        }
    ]
}
References

Affected packages

Git / github.com/typo3/typo3

Affected ranges

Type
GIT
Repo
https://github.com/typo3/typo3
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:typo3:typo3:10.4.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:typo3:typo3:10.4.1:*:*:*:*:*:*:*"
    ],
    "source": [
        "CPE_STRING",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "10.4.0"
        },
        {
            "last_affected": "10.4.0"
        },
        {
            "introduced": "10.4.1"
        },
        {
            "last_affected": "10.4.1"
        }
    ]
}

Affected versions

10.*
10.4.0
10.4.1
v10.*
v10.4.0
v10.4.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-11063.json"