First published: Thu Aug 12 2021(Updated: )
An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. MWOAuthConsumerSubmitControl.php does not ensure that the length of an RSA key will fit in a MySQL blob.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wikimedia MediaWiki | <=1.35.2 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-31556 is classified as a medium severity vulnerability due to its potential impact on RSA key storage.
To fix CVE-2021-31556, update to MediaWiki version 1.35.2 or later, as well as the relevant Fedora packages.
CVE-2021-31556 is caused by the MWOAuthConsumerSubmitControl.php not enforcing proper length limits for RSA keys in MySQL.
CVE-2021-31556 affects MediaWiki versions up to and including 1.35.2 and specific versions of Fedora.
Yes, CVE-2021-31556 can potentially be exploited remotely if an attacker is able to manipulate RSA key submissions.