{"id":"GHSA-cgr9-h9qq-x9fx","summary":"TYPO3 Authentication Bypass via Salted user password hashes extension","details":"Withdrawn: `typo3/cms-saltedpasswords` is not the correct package.\nSee: https://github.com/github/advisory-database/pull/3488\n\nThe TYPO3 Security - Salted user password hashes (t3sec_saltedpw) extension before 0.2.13 for TYPO3 allows remote attackers to bypass authentication via unspecified vectors.","aliases":["CVE-2010-1022"],"modified":"2026-09-10T03:49:22.214137541Z","published":"2022-05-02T06:18:14Z","withdrawn":"2024-02-14T15:09:19Z","database_specific":{"nvd_published_at":"2010-03-19T19:00:00Z","cwe_ids":["CWE-287"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-02-07T22:30:03Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2010-1022"},{"type":"PACKAGE","url":"https://github.com/TYPO3-CMS/saltedpasswords"},{"type":"WEB","url":"https://web.archive.org/web/20101125125343/http://secunia.com/advisories/38992"},{"type":"WEB","url":"https://web.archive.org/web/20200228221050/http://www.securityfocus.com/bid/38799"},{"type":"WEB","url":"http://typo3.org/extensions/repository/view/t3sec_saltedpw/0.2.13"},{"type":"WEB","url":"http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006"}],"affected":[{"package":{"name":"typo3/cms-saltedpasswords","ecosystem":"Packagist","purl":"pkg:composer/typo3/cms-saltedpasswords"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.2.13"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-cgr9-h9qq-x9fx/GHSA-cgr9-h9qq-x9fx.json"}}],"schema_version":"1.9.0"}