PT-2020-6813 · Oathauth+3 · Oathauth+3

Suffusion_Of_Yellow

·

Published

2020-09-25

·

Updated

2024-03-06

·

CVE-2020-25827

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions prior to 1.31.10 MediaWiki versions 1.32.x through 1.34.x before 1.34.4
Description The issue is related to insufficient restriction of authentication attempts in the OATHAuth extension for MediaWiki. This can be exploited by a remote attacker to bypass security restrictions using a brute force attack. For wikis using OATHAuth on a farm or cluster, such as via CentralAuth, rate limiting of OATH tokens is only done on a single site level, allowing multiple requests to be made across many wikis or sites concurrently.
Recommendations For MediaWiki versions prior to 1.31.10, update to version 1.31.10 or later. For MediaWiki versions 1.32.x through 1.34.x, update to version 1.34.4 or later. As a temporary workaround, consider implementing additional rate limiting measures for OATH tokens across all sites in a farm or cluster to minimize the risk of exploitation.

Exploit

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3022
ALT-PU-2020-3055
BDU:2022-07046
BIT-MEDIAWIKI-2020-25827
CVE-2020-25827
DLA-2379-1
DLA-2379-2
DLA-2379-3
DSA-4767-1
GHSA-RQVJ-FC2X-99Q6
MGASA-2020-0381

Affected Products

Alt Linux
Centralauth
Mediawiki
Oathauth