Vulnerability Name: CVE-2015-8624 (CCN-110281) Assigned: 2015-12-23 Published: 2015-12-23 Updated: 2017-03-27 Summary: The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 does not perform token comparison in constant time before determining if a debugging message should be logged, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8623 . CVSS v3 Severity: 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H )7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): RequiredScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N )4.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:U/RC:R )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): LowAvailibility (A): None
CVSS v2 Severity: 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): PartialAvailibility (A): None
Vulnerability Type: CWE-352 Vulnerability Consequences: Bypass Security References: Source: MITRE Type: CNACVE-2015-8624 Source: CCN Type: oss-sec Mailing List, Wed, 23 Dec 2015 14:06:58 -0500 (EST)Re: CVE requests for MediaWiki 1.26.1, 1.25.4, 1.24.5 and 1.23.12 Source: MLIST Type: Mailing List, Patch, Third Party Advisory[oss-security] 20151221 CVE requests for MediaWiki 1.26.1, 1.25.4, 1.24.5 and 1.23.12 Source: MLIST Type: Mailing List, Patch, Third Party Advisory[oss-security] 20151223 Re: CVE requests for MediaWiki 1.26.1, 1.25.4, 1.24.5 and 1.23.12 Source: XF Type: UNKNOWNmediawiki-cve20158624-sec-bypass(110281) Source: MLIST Type: Patch, Release Notes, Vendor Advisory[MediaWiki-announce] 20151221 [MediaWiki-announce] Security Release: 1.26.1, 1.25.4, 1.24.5 and 1.23.12 Source: CONFIRM Type: Patch, Third Party Advisoryhttps://phabricator.wikimedia.org/T119309 Source: CCN Type: MediaWiki Web siteMediaWiki Source: CCN Type: WhiteSource Vulnerability DatabaseCVE-2015-8624 Vulnerable Configuration: Configuration 1 :cpe:/a:mediawiki:mediawiki:*:*:*:*:*:*:*:* (Version <= 1.23.11)OR cpe:/a:mediawiki:mediawiki:1.24.0:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.24.1:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.24.2:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.24.3:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.24.4:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.25.0:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.25.1:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.25.2:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.25.3:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.26.0:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:mediawiki:mediawiki:1.26.1:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.25.4:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.24.5:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.23.12:*:*:*:*:*:*:* Denotes that component is vulnerable Oval Definitions BACK
mediawiki mediawiki *
mediawiki mediawiki 1.24.0
mediawiki mediawiki 1.24.1
mediawiki mediawiki 1.24.2
mediawiki mediawiki 1.24.3
mediawiki mediawiki 1.24.4
mediawiki mediawiki 1.25.0
mediawiki mediawiki 1.25.1
mediawiki mediawiki 1.25.2
mediawiki mediawiki 1.25.3
mediawiki mediawiki 1.26.0
mediawiki mediawiki 1.26.1
mediawiki mediawiki 1.25.4
mediawiki mediawiki 1.24.5
mediawiki mediawiki 1.23.12