GHSA-cgr9-h9qq-x9fx

Suggest an improvement
Source
https://github.com/advisories/GHSA-cgr9-h9qq-x9fx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-cgr9-h9qq-x9fx/GHSA-cgr9-h9qq-x9fx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-cgr9-h9qq-x9fx
Aliases
  • CVE-2010-1022
Withdrawn
2024-02-14T15:09:19Z
Published
2022-05-02T06:18:14Z
Modified
2026-09-10T03:49:22Z
Summary
TYPO3 Authentication Bypass via Salted user password hashes extension
Details

Withdrawn: typo3/cms-saltedpasswords is not the correct package. See: https://github.com/github/advisory-database/pull/3488

The TYPO3 Security - Salted user password hashes (t3sec_saltedpw) extension before 0.2.13 for TYPO3 allows remote attackers to bypass authentication via unspecified vectors.

Database specific
{
    "cwe_ids":  [
        "CWE-287"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2024-02-07T22:30:03Z",
    "nvd_published_at":  "2010-03-19T19:00:00Z",
    "severity":  "HIGH"
}
References

Affected packages

Packagist / typo3/cms-saltedpasswords

Package

Name
typo3/cms-saltedpasswords
Purl
pkg:composer/typo3/cms-saltedpasswords

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.2.13

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-cgr9-h9qq-x9fx/GHSA-cgr9-h9qq-x9fx.json"