{"id":"CVE-2024-36042","aliases":["GHSA-4w54-wwc9-x62c"],"url":"https://o3.security/vulnerability/CVE-2024-36042","summary":"Silverpeas authentication bypass","details":"Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.","published":"2024-06-03T05:47:04.246Z","modified":"2026-08-08T03:47:42.195398167Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.silverpeas.core:silverpeas-core","fixedVersion":"6.3.5"}],"fix":null,"references":[{"type":"WEB","url":"https://gist.github.com/ChrisPritchard/4b6d5c70d9329ef116266a6c238dcb2d"},{"type":"WEB","url":"https://github.com/Silverpeas/Silverpeas-Core/tags"},{"type":"WEB","url":"https://silverpeas.org/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/36xxx/CVE-2024-36042.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-36042"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:47:42.195398167Z"}}