PT-2023-18772 · Mediawiki+1 · Mediawiki+1

Bawolff

·

Published

2023-01-20

·

Updated

2024-08-20

·

CVE-2023-22912

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions prior to 1.35.9 MediaWiki versions 1.36.x through 1.38.x before 1.38.5 MediaWiki versions 1.39.x before 1.39.1
Description An issue was discovered in MediaWiki where the CheckUser TokenManager insecurely uses AES-CTR encryption with a repeated nonce, allowing an adversary to decrypt.
Recommendations For versions prior to 1.35.9, update to version 1.35.9 or later. For versions 1.36.x through 1.38.x before 1.38.5, update to version 1.38.5 or later. For versions 1.39.x before 1.39.1, update to version 1.39.1 or later.

Exploit

Fix

Use of Insufficiently Random Values

Weakness Enumeration

Related Identifiers

ALT-PU-2023-4877
ALT-PU-2024-11168
ALT-PU-2024-1228
BIT-MEDIAWIKI-2023-22912
CVE-2023-22912

Affected Products

Alt Linux
Mediawiki