{"id":"CVE-2024-36042","details":"Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.","aliases":["GHSA-4w54-wwc9-x62c"],"modified":"2026-08-12T03:51:25.970760484Z","published":"2024-06-03T05:47:04.246Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/36xxx/CVE-2024-36042.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://gist.github.com/ChrisPritchard/4b6d5c70d9329ef116266a6c238dcb2d"},{"type":"WEB","url":"https://github.com/Silverpeas/Silverpeas-Core/tags"},{"type":"WEB","url":"https://silverpeas.org/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/36xxx/CVE-2024-36042.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-36042"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/silverpeas/silverpeas-core","events":[{"introduced":"0"},{"fixed":"3e2a80b0d8a1f75c497dce2f1be4e91e8f19ecfd"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"6.3.5"}],"source":["DESCRIPTION","CPE_RANGE"],"cpe":"cpe:2.3:a:silverpeas:silverpeas:*:*:*:*:*:*:*:*"}}],"versions":["6.3","6.0-rc3","6.0-rc2","6.0-rc1","6.0-beta1","6.0-alpha3","6.0-alpha2","6.0-alpha1","core-5.12","core-5.11","core-5.7","core-5.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-36042.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}