Vulnerability Name: | CVE-2015-8623 (CCN-110279) | ||||||||||||||||||||||||||||||||||||
Assigned: | 2015-12-23 | ||||||||||||||||||||||||||||||||||||
Published: | 2015-12-23 | ||||||||||||||||||||||||||||||||||||
Updated: | 2017-03-27 | ||||||||||||||||||||||||||||||||||||
Summary: | The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12 and 1.24.x before 1.24.5 does not perform token comparison in constant time before returning, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8624. | ||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) 7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
4.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:U/RC:R)
| ||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-352 | ||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-8623 Source: CCN Type: oss-sec Mailing List, Wed, 23 Dec 2015 14:06:58 -0500 (EST) Re: CVE requests for MediaWiki 1.26.1, 1.25.4, 1.24.5 and 1.23.12 Source: MLIST Type: Mailing List, Patch, Third Party Advisory [oss-security] 20151221 CVE requests for MediaWiki 1.26.1, 1.25.4, 1.24.5 and 1.23.12 Source: MLIST Type: Mailing List, Patch, Third Party Advisory [oss-security] 20151223 Re: CVE requests for MediaWiki 1.26.1, 1.25.4, 1.24.5 and 1.23.12 Source: XF Type: UNKNOWN mediawiki-cve20158623-sec-bypass(110279) Source: CONFIRM Type: Issue Tracking, Third Party Advisory https://gerrit.wikimedia.org/r/#/c/156336/5/includes/User.php Source: MLIST Type: Patch, Release Notes, Vendor Advisory [MediaWiki-announce] 20151221 [MediaWiki-announce] Security Release: 1.26.1, 1.25.4, 1.24.5 and 1.23.12 Source: CONFIRM Type: Patch, Third Party Advisory https://phabricator.wikimedia.org/T119309 Source: CCN Type: MediaWiki Web site MediaWiki Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-8623 | ||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
BACK |