First published: Wed Mar 30 2022(Updated: )
An issue was discovered in MediaWiki through 1.37.1. The CentralAuth extension mishandles a ttl issue for groups expiring in the future.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki MediaWiki | <=1.37.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28205 is a vulnerability in MediaWiki version 1.37.1 that affects the CentralAuth extension.
The severity of CVE-2022-28205 is critical with a CVSS score of 9.8.
CVE-2022-28205 affects MediaWiki version 1.37.1 through the mishandling of a ttl issue in the CentralAuth extension.
To mitigate the impact of CVE-2022-28205, it is recommended to upgrade MediaWiki to a version that includes the patch for this vulnerability.
More information about CVE-2022-28205 can be found in the references provided: [Link 1](https://gerrit.wikimedia.org/r/q/Ic6ba1a37b78df5b342ceeba4c1493dbde583b81f), [Link 2](https://phabricator.wikimedia.org/T302248), [Link 3](https://security.gentoo.org/glsa/202305-24).