{"id":"CVE-2024-36042","aliases":["GHSA-4w54-wwc9-x62c"],"url":"https://o3.security/vulnerability/CVE-2024-36042","summary":"Silverpeas authentication bypass","details":"Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.","published":"2024-06-03T05:47:04.246Z","modified":"2026-08-12T03:51:25.970760484Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.silverpeas.core:silverpeas-core","fixedVersion":"6.3.5"}],"fix":{"url":"https://github.com/Silverpeas/Silverpeas-Core/commit/11fb5e21c252ce4751b85fccf5b8076156e0b4f0","label":"Silverpeas/Silverpeas-Core@11fb5e2"},"references":[{"type":"WEB","url":"https://gist.github.com/ChrisPritchard/4b6d5c70d9329ef116266a6c238dcb2d"},{"type":"WEB","url":"https://github.com/Silverpeas/Silverpeas-Core/tags"},{"type":"WEB","url":"https://silverpeas.org/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/36xxx/CVE-2024-36042.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-36042"},{"type":"WEB","url":"https://github.com/Silverpeas/Silverpeas-Core/commit/11fb5e21c252ce4751b85fccf5b8076156e0b4f0"},{"type":"PACKAGE","url":"https://github.com/Silverpeas/Silverpeas-Core"},{"type":"WEB","url":"https://silverpeas.org"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:25.970760484Z"}}