CVE-2015-8008: High severity mediawiki vulnerability
Published Dec 29, 2017
·Updated
The OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/initiate, which allows attackers to bypass intended IP address access restrictions by making an API request with an existing token.
Affected Software
4 affected components
MediaWiki<1.25.3
fedoraproject fedora=21
fedoraproject fedora=22
fedoraproject fedora=23
Remediation
Patch Available
Event History
Dec 29, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8008?
CVE-2015-8008 is classified as a medium severity vulnerability.
2
How do I fix CVE-2015-8008?
To fix CVE-2015-8008, you should upgrade to MediaWiki version 1.25.3 or later, or apply relevant patches.
3
What type of vulnerability is CVE-2015-8008?
CVE-2015-8008 is an access control vulnerability that can allow unauthorized requests using existing tokens.
4
Which software versions are affected by CVE-2015-8008?
CVE-2015-8008 affects MediaWiki versions earlier than 1.25.3 and specific versions of Fedora.
5
How does CVE-2015-8008 impact security?
CVE-2015-8008 can potentially allow attackers to bypass IP address access restrictions, compromising system security.