PT-2020-17370 · Mediawiki+1 · Mediawiki Casauth Extension+1

Sudozero

·

Published

2020-12-21

·

Updated

2024-03-06

·

CVE-2020-35623

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki CasAuth extension versions through 1.35.1
Description An issue was discovered due to improper username validation, allowing user impersonation with trivial manipulations of certain characters within a given username. An ordinary user may be able to login as a "bureaucrat user" who has a similar username, as demonstrated by usernames that differ only in bidirectional override symbols or blank space.
Recommendations For MediaWiki CasAuth extension versions through 1.35.1, update to a version that fixes the improper username validation issue to prevent user impersonation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1712
ALT-PU-2021-2091
BIT-MEDIAWIKI-2020-35623
CVE-2020-35623

Affected Products

Alt Linux
Mediawiki Casauth Extension