PT-2023-18772 · Mediawiki+1 · Mediawiki+1

Bawolff

·

Publicado

2023-01-20

·

Atualizado

2024-08-20

·

CVE-2023-22912

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions prior to 1.35.9 MediaWiki versions 1.36.x through 1.38.x before 1.38.5 MediaWiki versions 1.39.x before 1.39.1
Description An issue was discovered in MediaWiki where the CheckUser TokenManager insecurely uses AES-CTR encryption with a repeated nonce, allowing an adversary to decrypt.
Recommendations For versions prior to 1.35.9, update to version 1.35.9 or later. For versions 1.36.x through 1.38.x before 1.38.5, update to version 1.38.5 or later. For versions 1.39.x before 1.39.1, update to version 1.39.1 or later.

Exploit

Correção

Use of Insufficiently Random Values

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-4877
ALT-PU-2024-11168
ALT-PU-2024-1228
BIT-MEDIAWIKI-2023-22912
CVE-2023-22912

Produtos afetados

Alt Linux
Mediawiki