GHSA-jqr8-q455-xx45: TYPO3 Brute Force Protection Bypass in backend login
The backend login has a basic brute force protection implementation which pauses for 5 seconds if wrong credentials are given. This pause however could be bypassed by forging a special request, making brute force attacks on backend editor credentials more feasible.
References
- github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/2015-07-01-5.yaml
- github.com/TYPO3/typo3
- github.com/TYPO3/typo3/commit/0b67290bbd941c07b0101bbfd6c7aadcbb93c75c
- github.com/TYPO3/typo3/commit/0f3fb37674688aba5a44ca6f5df7f8a327a5b5f6
- github.com/advisories/GHSA-jqr8-q455-xx45
- typo3.org/security/advisory/typo3-core-sa-2015-006
- typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2015-006
Detect and mitigate GHSA-jqr8-q455-xx45 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →