Bugzilla – Bug 919006
VUL-0: CVE-2015-2047: typo3-cms-4_5, typo3-cms-4_6: Authentication Bypass
Last modified: 2015-03-15 19:20:47 UTC
It has been discovered that TYPO3 CMS is vulnerable to Authentication Bypass. Frontend users can be authenticated by only knowing their username. TYPO3 installations are affected, if all of the following applies: TYPO3 Version 4.3.0 to 4.3.14, 4.4.0 to 4.4.15, 4.5.0 to 4.5.39 or 4.6.0 to 4.6.18 users/access restricted frontend area (frontend login) system extension rsaauth is loaded system extension rsaauth is configured for frontend usage like that: $GLOBALS['TYPO3_CONF_VARS']['FE']['loginSecurityLevel'] = 'rsa' References: https://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2015-001/ http://www.debian.org/security/2015/dsa-3164
bugbot adjusting priority
Fixed with submit request 287428.