Vulnerability CVE-2015-8008


Published: 2017-12-29

Description:
The OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/initiate, which allows attackers to bypass intended IP address access restrictions by making an API request with an existing token.

Type:

CWE-284

(Improper Access Control)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Mediawiki -> Mediawiki 
Fedoraproject -> Fedora 

 References:
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/170961.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/170979.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171007.html
http://www.openwall.com/lists/oss-security/2015/10/29/14
http://www.securityfocus.com/bid/77379
http://www.securitytracker.com/id/1034028
https://bugzilla.redhat.com/show_bug.cgi?id=1273353
https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-October/000182.html
https://phabricator.wikimedia.org/T103022

Copyright 2024, cxsecurity.com

 

Back to Top