Description
The System extension Install tool in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 creates the encryption key with an insufficiently random seed, which makes it easier for attackers to crack the key.
Remediation
References
Related Vulnerabilities
WordPress Plugin Rent-A-Car TimThumb Arbitrary File Upload (1.0)
WordPress Plugin Register Plus 'wp-login.php' Multiple Cross-Site Scripting Vulnerabilities (3.5.1)
Moodle Credentials Management Errors Vulnerability (CVE-2011-4587)
OpenSSL Cryptographic Issues Vulnerability (CVE-2009-2409)
TYPO3 Deserialization of Untrusted Data Vulnerability (CVE-2019-19849)