Vulnerability Name: | CVE-2021-31556 (CCN-207886) | ||||||||||||
Assigned: | 2021-04-21 | ||||||||||||
Published: | 2021-04-21 | ||||||||||||
Updated: | 2021-11-28 | ||||||||||||
Summary: | An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. MWOAuthConsumerSubmitControl.php does not ensure that the length of an RSA key will fit in a MySQL blob. | ||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-327 | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-31556 Source: XF Type: UNKNOWN mediawiki-cve202131556-sec-bypass(207886) Source: MISC Type: Patch, Vendor Advisory https://gerrit.wikimedia.org/r/q/I13ff0350a9a0a3cd5ab3e1f82dd0d8d9c13cf9e9 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-56d8173b5e Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-3dd1b66cbf Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-eee8b7514f Source: CCN Type: Phabricator T277380 Oauth extension for MediaWiki Source: MISC Type: Permissions Required, Vendor Advisory https://phabricator.wikimedia.org/T277380 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |