CVE-2014-3944
Published Jun 3, 2014
Last updated 10 years ago
Overview
- Description
- The Authentication component in TYPO3 6.2.0 before 6.2.3 does not properly invalidate timed out user sessions, which allows remote attackers to bypass authentication via unspecified vectors.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5.8
- Impact score
- 4.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-287
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:typo3:typo3:6.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C7715060-1441-4CF9-BEDF-91D28FE31ECC" }, { "criteria": "cpe:2.3:a:typo3:typo3:6.2.0:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7183456A-52B4-4386-8979-A2ECEA9959FE" }, { "criteria": "cpe:2.3:a:typo3:typo3:6.2.0:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "16EEC79F-3293-451C-864E-9CE020F6C730" }, { "criteria": "cpe:2.3:a:typo3:typo3:6.2.0:beta3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8FD27EAD-04D5-4C55-952E-020954B90CEF" }, { "criteria": "cpe:2.3:a:typo3:typo3:6.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "99262E73-E4A7-4657-A32E-3C289C052675" }, { "criteria": "cpe:2.3:a:typo3:typo3:6.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E230A800-B2DE-4ED4-9C6B-961832C39900" } ], "operator": "OR" } ] } ]