CVE-2020-25827

CVSS v3.1 7.5 (High)
75% Progress
CVSS v2.0 5 (Medium)
50% Progress
EPSS 0.17 % (55th)
0.17% Progress
Affected Products 2
Advisories 3

An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limiting of OATH tokens is only done on a single site level. Thus, multiple requests can be made across many wikis/sites concurrently.

Weaknesses
CWE-307
Improper Restriction of Excessive Authentication Attempts
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2020-09-27 21:15:12
(4 years ago)
Updated Date
2023-11-07 03:20:25
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mediawiki prior 1.31.10 version cpe:2.3:a:mediawiki:mediawiki < 1.31.10
  Mediawiki from 1.32.0 version and prior 1.34.4 version cpe:2.3:a:mediawiki:mediawiki >= 1.32.0 < 1.34.4

Configuration #2

    CPE23 From Up To
  Fedoraproject Fedora 33 cpe:2.3:o:fedoraproject:fedora:33
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...