GHSA-r6mm-wmhf-849m

Suggest an improvement
Source
https://github.com/advisories/GHSA-r6mm-wmhf-849m
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-r6mm-wmhf-849m/GHSA-r6mm-wmhf-849m.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-r6mm-wmhf-849m
Published
2024-06-05T17:28:47Z
Modified
2024-12-02T05:54:44.363340Z
Summary
Time-Based Information Disclosure Vulnerability in Flow
Details

The PersistedUsernamePasswordProvider was prone to a information disclosure of account existance based on timing attacks as the hashing of passwords was only done in case an account was found. We changed the core so that the provider always does a password comparison in case credentials were submitted at all.

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-06-05T17:28:47Z"
}
References

Affected packages

Packagist / typo3/flow

Package

Name
typo3/flow
Purl
pkg:composer/typo3/flow

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.3.0
Fixed
2.3.16

Affected versions

2.*

2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.3.10
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15

Packagist / typo3/flow

Package

Name
typo3/flow
Purl
pkg:composer/typo3/flow

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.0.0
Fixed
3.0.10

Affected versions

3.*

3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9

Packagist / typo3/flow

Package

Name
typo3/flow
Purl
pkg:composer/typo3/flow

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.1.0
Fixed
3.1.7

Affected versions

3.*

3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6

Packagist / typo3/flow

Package

Name
typo3/flow
Purl
pkg:composer/typo3/flow

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.2.0
Fixed
3.2.7

Affected versions

3.*

3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6

Packagist / typo3/flow

Package

Name
typo3/flow
Purl
pkg:composer/typo3/flow

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.3.0
Fixed
3.3.5

Affected versions

3.*

3.3.0
3.3.1
3.3.2
3.3.3
3.3.4