Vulnerability Name: CVE-2015-8626 (CCN-110287) Assigned: 2015-12-23 Published: 2015-12-23 Updated: 2017-03-27 Summary: The User::randomPassword function in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 generates passwords smaller than $wgMinimalPasswordLength, which makes it easier for remote attackers to obtain access via a brute-force attack. CVSS v3 Severity: 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H )8.6 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N )4.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:U/RC:R )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): LowAvailibility (A): None
CVSS v2 Severity: 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): NoneAvailibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): PartialAvailibility (A): None
Vulnerability Type: CWE-255 Vulnerability Consequences: Gain Access References: Source: MITRE Type: CNACVE-2015-8626 Source: CCN Type: oss-sec Mailing List, Wed, 23 Dec 2015 14:06:58 -0500 (EST)Re: CVE requests for MediaWiki 1.26.1, 1.25.4, 1.24.5 and 1.23.12 Source: MLIST Type: Mailing List, Patch, Third Party Advisory[oss-security] 20151221 CVE requests for MediaWiki 1.26.1, 1.25.4, 1.24.5 and 1.23.12 Source: MLIST Type: Mailing List, Patch, Third Party Advisory[oss-security] 20151223 Re: CVE requests for MediaWiki 1.26.1, 1.25.4, 1.24.5 and 1.23.12 Source: XF Type: UNKNOWNmediawiki-cve20158626-weak-security(110287) Source: MLIST Type: Patch, Release Notes, Vendor Advisory[MediaWiki-announce] 20151221 [MediaWiki-announce] Security Release: 1.26.1, 1.25.4, 1.24.5 and 1.23.12 Source: CONFIRM Type: Patch, Third Party Advisoryhttps://phabricator.wikimedia.org/T115522 Source: CCN Type: MediaWiki Web siteMediaWiki Source: CCN Type: WhiteSource Vulnerability DatabaseCVE-2015-8626 Vulnerable Configuration: Configuration 1 :cpe:/a:mediawiki:mediawiki:*:*:*:*:*:*:*:* (Version <= 1.23.11)OR cpe:/a:mediawiki:mediawiki:1.24.0:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.24.1:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.24.2:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.24.3:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.24.4:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.25.0:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.25.1:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.25.2:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.25.3:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.26.0:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:mediawiki:mediawiki:1.26.1:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.25.4:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.24.5:*:*:*:*:*:*:* OR cpe:/a:mediawiki:mediawiki:1.23.12:*:*:*:*:*:*:* Denotes that component is vulnerable Oval Definitions BACK
mediawiki mediawiki *
mediawiki mediawiki 1.24.0
mediawiki mediawiki 1.24.1
mediawiki mediawiki 1.24.2
mediawiki mediawiki 1.24.3
mediawiki mediawiki 1.24.4
mediawiki mediawiki 1.25.0
mediawiki mediawiki 1.25.1
mediawiki mediawiki 1.25.2
mediawiki mediawiki 1.25.3
mediawiki mediawiki 1.26.0
mediawiki mediawiki 1.26.1
mediawiki mediawiki 1.25.4
mediawiki mediawiki 1.24.5
mediawiki mediawiki 1.23.12