Vulnerability Name: | CVE-2015-8009 (CCN-107711) | ||||||||||||
Assigned: | 2015-10-29 | ||||||||||||
Published: | 2015-10-29 | ||||||||||||
Updated: | 2017-09-15 | ||||||||||||
Summary: | The MWOAuthDataStore::lookup_token function in Extension:OAuth for MediaWiki 1.25.x before 1.25.3, 1.24.x before 1.24.4, and before 1.23.11 does not properly validate the signature when checking the authorization signature, which allows remote registered Consumers to use another Consumer's credentials by leveraging knowledge of the credentials. | ||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
4.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-255 | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-8009 Source: CCN Type: SECTRACK ID: 1034028 MediaWiki Multiple Bugs Let Remote Users Obtain Potentially Sensitive Information and Conduct Cross-Site Scripting Attacks and Let Remote Authenticated Users Bypass Security and Deny Service Source: MLIST Type: Mailing List, VDB Entry [oss-security] 20151029 Re: CVE Request: MediaWiki 1.25.3, 1.24.4 and 1.23.11 Source: SECTRACK Type: UNKNOWN 1034028 Source: XF Type: UNKNOWN mediawiki-cve20158009-sec-bypass(107711) Source: CONFIRM Type: Exploit, Third Party Advisory https://phabricator.wikimedia.org/T103023 Source: CCN Type: MediaWiki Web site MediaWiki Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-8009 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
BACK |