CVE-2020-25827: High severity mediawiki vulnerability
An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limiting of OATH tokens is only done on a single site level. Thus, multiple requests can be made across many wikis/sites concurrently.
Other sources
An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.9 and 1.32.x through 1.34.x before 1.34.3. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limiting of OATH tokens is only done on a single site level. Thus, multiple requests can be made across many wikis/sites concurrently.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25827?
CVE-2020-25827 has been assigned a moderate severity rating due to its potential for OATH token abuse.
How do I fix CVE-2020-25827?
To fix CVE-2020-25827, upgrade to MediaWiki version 1.31.10, 1.34.4, or any later version.
Which versions of MediaWiki are affected by CVE-2020-25827?
CVE-2020-25827 affects MediaWiki versions from 1.31.0 to 1.31.9 and 1.34.0 to 1.34.3.
Does CVE-2020-25827 affect all installations of MediaWiki?
CVE-2020-25827 specifically affects MediaWiki instances using the OATHAuth extension in a farm or cluster setup.
What are the risks associated with CVE-2020-25827?
The risk associated with CVE-2020-25827 includes susceptibility to rate limiting bypass which could lead to unauthorized access.