CVE-2014-3945: TYPO3 vulnerable to authentication bypass via leveraging knowledge of password hash
(updated )
The Authentication component in TYPO3 before 6.2, when salting for password hashing is disabled, does not require knowledge of the cleartext password if the password hash is known, which allows remote attackers to bypass authentication and gain access to the backend by leveraging knowledge of a password hash.
References
Code Behaviors & Features
Detect and mitigate CVE-2014-3945 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →