CVE-2023-22912: Medium severity mediawiki vulnerability
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. CheckUser TokenManager insecurely uses AES-CTR encryption with a repeated (aka re-used) nonce, allowing an adversary to decrypt.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-22912.
What is the severity of CVE-2023-22912?
The severity of CVE-2023-22912 is medium with a severity value of 5.3.
What is the affected software for CVE-2023-22912?
The affected software for CVE-2023-22912 is MediaWiki versions 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1.
What is the description of CVE-2023-22912?
CVE-2023-22912 is an issue in MediaWiki versions before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1 where CheckUser TokenManager insecurely uses AES-CTR encryption with a repeated (aka re-used) nonce, allowing an adversary to decrypt.
Is there a reference for CVE-2023-22912?
Yes, you can find the reference for CVE-2023-22912 at https://phabricator.wikimedia.org/T315123.