CVE-2013-4304: High severity centralauth extension for mediawiki by brion vibber vulnerability
The CentralAuth extension for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 caches a valid CentralAuthUser object in the centralauthUser cookie even when a user has not successfully logged in, which allows remote attackers to bypass authentication without a password.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4304?
CVE-2013-4304 is considered to be a high-severity vulnerability due to its potential to bypass authentication.
How do I fix CVE-2013-4304?
To fix CVE-2013-4304, you should upgrade the CentralAuth extension for MediaWiki to version 1.19.8, 1.20.7, or 1.21.2 or later.
Which versions of MediaWiki are affected by CVE-2013-4304?
CVE-2013-4304 affects MediaWiki versions 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2.
What type of attack can exploit CVE-2013-4304?
CVE-2013-4304 allows remote attackers to bypass authentication without a password by exploiting the caching mechanism of the CentralAuth extension.
Is authentication secure for versions affected by CVE-2013-4304?
No, authentication is not secure for the affected versions of MediaWiki as the vulnerability allows unauthorized access.