CVE-2015-8626: Critical severity mediawiki vulnerability
The User::randomPassword function in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 generates passwords smaller than $wgMinimalPasswordLength, which makes it easier for remote attackers to obtain access via a brute-force attack.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8626?
CVE-2015-8626 has a moderate severity rating due to its potential for password brute-force attacks.
How do I fix CVE-2015-8626?
To fix CVE-2015-8626, upgrade MediaWiki to at least version 1.23.12, 1.24.5, 1.25.4, or 1.26.1.
What are the affected versions of MediaWiki for CVE-2015-8626?
CVE-2015-8626 affects MediaWiki versions prior to 1.23.12, 1.24.5, 1.25.4, and 1.26.1.
What kind of attack does CVE-2015-8626 allow?
CVE-2015-8626 allows remote attackers to conduct brute-force attacks to guess user passwords.
Is CVE-2015-8626 fixed in MediaWiki 1.23.12?
Yes, MediaWiki 1.23.12 and later versions have addressed the vulnerability described in CVE-2015-8626.