CVE-2025-32068: Revoking authorization of OAuth2 consumer does not invalidate refresh tokens
Published Apr 11, 2025
·Updated
Incorrect Authorization vulnerability in The Wikimedia Foundation Mediawiki - OAuth Extension allows Authentication Bypass.This issue affects Mediawiki - OAuth Extension: from 1.39 through 1.43.
Affected Software
1 affected component
Wikimedia Foundation Mediawiki - OAuth Extension>=1.39<=1.43
Event History
Apr 11, 2025
CVE Published
via MITRE·04:21 PM
Data Sourced
via MITRE·04:21 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Aug 27, 57485
Event
via NVD·12:56 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-32068?
The severity of CVE-2025-32068 is considered to be critical due to the potential for authentication bypass.
2
How do I fix CVE-2025-32068?
To fix CVE-2025-32068, upgrade the Mediawiki - OAuth Extension to a version higher than 1.43.
3
What versions of Mediawiki - OAuth Extension are affected by CVE-2025-32068?
CVE-2025-32068 affects Mediawiki - OAuth Extension versions from 1.39 to 1.43.
4
What impact does CVE-2025-32068 have on data security?
CVE-2025-32068 can potentially allow unauthorized users to access sensitive information due to authentication bypass.
5
Is user intervention required to mitigate CVE-2025-32068?
Yes, user intervention is required to mitigate CVE-2025-32068 by applying the appropriate software update.