First published: Fri Feb 28 2014(Updated: )
includes/User.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 terminates validation of a user token upon encountering the first incorrect character, which makes it easier for remote attackers to obtain access via a brute-force attack that relies on timing differences in responses to incorrect token guesses.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/mediawiki | <1.22.3 | 1.22.3 |
redhat/mediawiki | <1.21.6 | 1.21.6 |
redhat/mediawiki | <1.19.12 | 1.19.12 |
MediaWiki | <=1.19.11 | |
MediaWiki | =1.1.0 | |
MediaWiki | =1.10.0 | |
MediaWiki | =1.10.0-rc1 | |
MediaWiki | =1.10.0-rc2 | |
MediaWiki | =1.10.1 | |
MediaWiki | =1.10.2 | |
MediaWiki | =1.10.3 | |
MediaWiki | =1.10.4 | |
MediaWiki | =1.11 | |
MediaWiki | =1.11.0 | |
MediaWiki | =1.11.0-rc1 | |
MediaWiki | =1.11.1 | |
MediaWiki | =1.11.2 | |
MediaWiki | =1.12.0 | |
MediaWiki | =1.12.0-rc1 | |
MediaWiki | =1.12.1 | |
MediaWiki | =1.12.2 | |
MediaWiki | =1.12.3 | |
MediaWiki | =1.12.4 | |
MediaWiki | =1.13.0 | |
MediaWiki | =1.13.0-rc1 | |
MediaWiki | =1.13.0-rc2 | |
MediaWiki | =1.13.1 | |
MediaWiki | =1.13.2 | |
MediaWiki | =1.13.3 | |
MediaWiki | =1.13.4 | |
MediaWiki | =1.14.0 | |
MediaWiki | =1.14.0-rc1 | |
MediaWiki | =1.14.1 | |
MediaWiki | =1.15.0 | |
MediaWiki | =1.15.0-rc1 | |
MediaWiki | =1.15.1 | |
MediaWiki | =1.15.2 | |
MediaWiki | =1.15.3 | |
MediaWiki | =1.15.4 | |
MediaWiki | =1.15.5 | |
MediaWiki | =1.16.0 | |
MediaWiki | =1.16.0-beta1 | |
MediaWiki | =1.16.0-beta2 | |
MediaWiki | =1.16.0-beta3 | |
MediaWiki | =1.16.1 | |
MediaWiki | =1.16.2 | |
MediaWiki | =1.17 | |
MediaWiki | =1.17-beta_1 | |
MediaWiki | =1.17.0 | |
MediaWiki | =1.17.0-rc1 | |
MediaWiki | =1.17.1 | |
MediaWiki | =1.17.2 | |
MediaWiki | =1.17.3 | |
MediaWiki | =1.17.4 | |
MediaWiki | =1.18 | |
MediaWiki | =1.18-beta_1 | |
MediaWiki | =1.18.0 | |
MediaWiki | =1.18.0-rc1 | |
MediaWiki | =1.18.1 | |
MediaWiki | =1.18.2 | |
MediaWiki | =1.18.3 | |
MediaWiki | =1.19 | |
MediaWiki | =1.19-beta_1 | |
MediaWiki | =1.19-beta_2 | |
MediaWiki | =1.19.0 | |
MediaWiki | =1.19.1 | |
MediaWiki | =1.19.2 | |
MediaWiki | =1.19.3 | |
MediaWiki | =1.19.4 | |
MediaWiki | =1.19.5 | |
MediaWiki | =1.19.6 | |
MediaWiki | =1.19.7 | |
MediaWiki | =1.19.8 | |
MediaWiki | =1.19.9 | |
MediaWiki | =1.19.10 | |
MediaWiki | =1.20 | |
MediaWiki | =1.20.1 | |
MediaWiki | =1.20.2 | |
MediaWiki | =1.20.3 | |
MediaWiki | =1.20.4 | |
MediaWiki | =1.20.5 | |
MediaWiki | =1.20.6 | |
MediaWiki | =1.20.7 | |
MediaWiki | =1.20.8 | |
MediaWiki | =1.21 | |
MediaWiki | =1.21.1 | |
MediaWiki | =1.21.2 | |
MediaWiki | =1.21.3 | |
MediaWiki | =1.21.4 | |
MediaWiki | =1.21.5 | |
MediaWiki | =1.22.0 | |
MediaWiki | =1.22.1 | |
MediaWiki | =1.22.2 | |
<=1.19.11 | ||
=1.1.0 | ||
=1.10.0 | ||
=1.10.0-rc1 | ||
=1.10.0-rc2 | ||
=1.10.1 | ||
=1.10.2 | ||
=1.10.3 | ||
=1.10.4 | ||
=1.11 | ||
=1.11.0 | ||
=1.11.0-rc1 | ||
=1.11.1 | ||
=1.11.2 | ||
=1.12.0 | ||
=1.12.0-rc1 | ||
=1.12.1 | ||
=1.12.2 | ||
=1.12.3 | ||
=1.12.4 | ||
=1.13.0 | ||
=1.13.0-rc1 | ||
=1.13.0-rc2 | ||
=1.13.1 | ||
=1.13.2 | ||
=1.13.3 | ||
=1.13.4 | ||
=1.14.0 | ||
=1.14.0-rc1 | ||
=1.14.1 | ||
=1.15.0 | ||
=1.15.0-rc1 | ||
=1.15.1 | ||
=1.15.2 | ||
=1.15.3 | ||
=1.15.4 | ||
=1.15.5 | ||
=1.16.0 | ||
=1.16.0-beta1 | ||
=1.16.0-beta2 | ||
=1.16.0-beta3 | ||
=1.16.1 | ||
=1.16.2 | ||
=1.17 | ||
=1.17-beta_1 | ||
=1.17.0 | ||
=1.17.0-rc1 | ||
=1.17.1 | ||
=1.17.2 | ||
=1.17.3 | ||
=1.17.4 | ||
=1.18 | ||
=1.18-beta_1 | ||
=1.18.0 | ||
=1.18.0-rc1 | ||
=1.18.1 | ||
=1.18.2 | ||
=1.18.3 | ||
=1.19 | ||
=1.19-beta_1 | ||
=1.19-beta_2 | ||
=1.19.0 | ||
=1.19.1 | ||
=1.19.2 | ||
=1.19.3 | ||
=1.19.4 | ||
=1.19.5 | ||
=1.19.6 | ||
=1.19.7 | ||
=1.19.8 | ||
=1.19.9 | ||
=1.19.10 | ||
=1.20 | ||
=1.20.1 | ||
=1.20.2 | ||
=1.20.3 | ||
=1.20.4 | ||
=1.20.5 | ||
=1.20.6 | ||
=1.20.7 | ||
=1.20.8 | ||
=1.21 | ||
=1.21.1 | ||
=1.21.2 | ||
=1.21.3 | ||
=1.21.4 | ||
=1.21.5 | ||
=1.22.0 | ||
=1.22.1 | ||
=1.22.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2243 has been classified as a high-severity vulnerability due to its potential for remote exploitation.
To fix CVE-2014-2243, upgrade your MediaWiki installation to version 1.22.3 or later, or to 1.21.6 or later.
CVE-2014-2243 affects MediaWiki versions prior to 1.19.12, 1.20.x before 1.20.6, 1.21.x before 1.21.6, and 1.22.x before 1.22.3.
CVE-2014-2243 is a user token validation vulnerability that can be exploited via brute-force attacks.
There are no known workarounds for CVE-2014-2243; updating to a patched version is the only solution.