CVE-2020-25827

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/09/2020
Last modified:
07/11/2023

Description

An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limiting of OATH tokens is only done on a single site level. Thus, multiple requests can be made across many wikis/sites concurrently.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:* 1.31.10 (excluding)
cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:* 1.32.0 (including) 1.34.4 (excluding)
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*