CVE-2015-8009: Critical severity mediawiki vulnerability
The MWOAuthDataStore::lookuptoken function in Extension:OAuth for MediaWiki 1.25.x before 1.25.3, 1.24.x before 1.24.4, and before 1.23.11 does not properly validate the signature when checking the authorization signature, which allows remote registered Consumers to use another Consumer's credentials by leveraging knowledge of the credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8009?
CVE-2015-8009 is considered a medium severity vulnerability.
How do I fix CVE-2015-8009?
To fix CVE-2015-8009, you should upgrade to MediaWiki versions 1.25.3 or later, 1.24.4 or later, or 1.23.11 or later.
What is CVE-2015-8009 about?
CVE-2015-8009 is a vulnerability in the OAuth extension for MediaWiki that allows unauthorized access due to improper validation of authorization signatures.
Which versions of MediaWiki are affected by CVE-2015-8009?
CVE-2015-8009 affects MediaWiki versions 1.23.x before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3.
Can CVE-2015-8009 be exploited remotely?
Yes, CVE-2015-8009 can be exploited remotely by registered Consumers to access another Consumer's credentials.