PT-2021-3955 · Unknown+2 · Mysql Server+3

Published

2021-03-19

·

Updated

2024-03-06

·

CVE-2021-31556

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MediaWiki versions through 1.35.2
Description An issue was discovered in the Oauth extension for MediaWiki. The problem lies in MWOAuthConsumerSubmitControl.php, which does not ensure that the length of an RSA key will fit in a MySQL blob. This could potentially allow a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For MediaWiki versions through 1.35.2, as a temporary workaround, consider restricting the use of the Oauth extension until a patch is available. Ensure that RSA key lengths are validated to fit within the MySQL blob size limits to prevent potential issues. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1991
ALT-PU-2021-2091
BDU:2021-04474
BIT-MEDIAWIKI-2021-31556
CVE-2021-31556

Affected Products

Alt Linux
Mediawiki
Mysql Server
Oauth Extension