PT-2014-4859 · Wikimedia+1 · Mediawiki+1

Published

2014-04-03

·

Updated

2014-07-29

·

CVE-2014-2665

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions prior to 1.19.14 MediaWiki versions 1.20.x MediaWiki versions 1.21.x prior to 1.21.8 MediaWiki versions 1.22.x prior to 1.22.5
Description The issue makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account, as demonstrated by tracking the victim's activity, related to a "login CSRF" issue. This occurs because the includes/specials/SpecialChangePassword.php file in MediaWiki does not properly handle a correctly authenticated but unintended login attempt.
Recommendations For MediaWiki versions prior to 1.19.14, update to version 1.19.14 or later. For MediaWiki versions 1.20.x, update to a version outside of the 1.20.x range, such as 1.19.14 or later, or 1.21.8 or later. For MediaWiki versions 1.21.x prior to 1.21.8, update to version 1.21.8 or later. For MediaWiki versions 1.22.x prior to 1.22.5, update to version 1.22.5 or later.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1960
CVE-2014-2665
DSA-2891-1
MGASA-2014-0157

Affected Products

Alt Linux
Mediawiki