
Cloud Vulnerability DB
A community-led vulnerabilities database
A time-based information disclosure vulnerability was discovered in TYPO3 Flow, identified as Flow-SA-2016-001. The vulnerability was disclosed on November 1st, 2016, affecting all Flow versions before 2.3.16, 3.0.10, 3.1.7, 3.2.7, and 3.3.5. This security issue was classified as having low severity (Neos Blog).
The vulnerability resided in the PersistedUsernamePasswordProvider component of Flow. The core issue was that password hashing operations were only performed when an account was found in the system, creating a timing discrepancy that could be exploited. The vulnerability has been assigned a CVSS v3.0 score with the following vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/CR:L/IR:L/AR:L (Neos Blog).
The vulnerability could lead to information disclosure, specifically allowing attackers to determine the existence of user accounts through timing-based attacks. This could potentially be used as a stepping stone for further targeted attacks (GitHub Advisory).
The vulnerability could be exploited remotely through timing attacks against the authentication system. The attack complexity is considered low, requiring no privileges or user interaction to execute (Neos Blog).
The vulnerability has been fixed in Flow versions 2.3.16, 3.0.10, 3.1.7, 3.2.7, and 3.3.5. The fix ensures that the provider always performs a password comparison when credentials are submitted, regardless of whether an account exists or not. Users are advised to update to these patched versions (GitHub Advisory, Neos Blog).
The vulnerability was discovered by Kevin Fischer and Coresec Systems, who responsibly disclosed it to the Neos team. The Neos team subsequently developed and reviewed the fixes (Neos Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."