CVE-2022-28205: Critical severity mediawiki vulnerability
An issue was discovered in MediaWiki through 1.37.1. The CentralAuth extension mishandles a ttl issue for groups expiring in the future.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-28205?
CVE-2022-28205 is a vulnerability in MediaWiki version 1.37.1 that affects the CentralAuth extension.
What is the severity of CVE-2022-28205?
The severity of CVE-2022-28205 is critical with a CVSS score of 9.8.
How does CVE-2022-28205 affect MediaWiki?
CVE-2022-28205 affects MediaWiki version 1.37.1 through the mishandling of a ttl issue in the CentralAuth extension.
How can I mitigate the impact of CVE-2022-28205?
To mitigate the impact of CVE-2022-28205, it is recommended to upgrade MediaWiki to a version that includes the patch for this vulnerability.
Where can I find more information about CVE-2022-28205?
More information about CVE-2022-28205 can be found in the references provided: [Link 1](https://gerrit.wikimedia.org/r/q/Ic6ba1a37b78df5b342ceeba4c1493dbde583b81f), [Link 2](https://phabricator.wikimedia.org/T302248), [Link 3](https://security.gentoo.org/glsa/202305-24).