First published: Fri Jan 20 2023(Updated: )
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. CheckUser TokenManager insecurely uses AES-CTR encryption with a repeated (aka re-used) nonce, allowing an adversary to decrypt.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki MediaWiki | <1.35.9 | |
MediaWiki MediaWiki | >=1.36.0<1.38.5 | |
MediaWiki MediaWiki | =1.39.0 | |
MediaWiki MediaWiki | =1.39.0-rc0 | |
MediaWiki MediaWiki | =1.39.0-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-22912.
The severity of CVE-2023-22912 is medium with a severity value of 5.3.
The affected software for CVE-2023-22912 is MediaWiki versions 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1.
CVE-2023-22912 is an issue in MediaWiki versions before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1 where CheckUser TokenManager insecurely uses AES-CTR encryption with a repeated (aka re-used) nonce, allowing an adversary to decrypt.
Yes, you can find the reference for CVE-2023-22912 at https://phabricator.wikimedia.org/T315123.