Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27230 | A deterministic three‑character prefix in the Password Generation component of TYPO3 CMS versions 12.0.0–12.4.36 and 13.0.0–13.4.17 reduces entropy, allowing attackers to carry out brute‑force attacks more quickly. |
Github GHSA |
GHSA-p5jq-5383-qvc7 | TYPO3 CMS uses insufficient entropy when generating passwords |
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-core-sa-2025-019 |
|
Wed, 10 Sep 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 09 Sep 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Sep 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Typo3
Typo3 typo3 |
|
| Vendors & Products |
Typo3
Typo3 typo3 |
Tue, 09 Sep 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A deterministic three‑character prefix in the Password Generation component of TYPO3 CMS versions 12.0.0–12.4.36 and 13.0.0–13.4.17 reduces entropy, allowing attackers to carry out brute‑force attacks more quickly. | |
| Title | Insufficient Entropy in Password Generation | |
| Weaknesses | CWE-331 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2025-09-09T19:31:09.254Z
Reserved: 2025-09-07T19:01:20.436Z
Link: CVE-2025-59015
Updated: 2025-09-09T19:31:06.091Z
Status : Analyzed
Published: 2025-09-09T09:15:40.057
Modified: 2025-09-10T13:42:59.310
Link: CVE-2025-59015
No data.
OpenCVE Enrichment
Updated: 2025-09-09T21:31:39Z
EUVD
Github GHSA