CVE-2020-25827
Last modified
CVE-2020-25827 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limiting of OATH tokens is only done on a single site level. EPSS estimates a 1.75% chance of exploitation in the next 30 days.
Description
An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limiting of OATH tokens is only done on a single site level. Thus, multiple requests can be made across many wikis/sites concurrently.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mediawiki | Mediawiki | < 1.31.10 |
| Mediawiki | Mediawiki | >= 1.32.0, < 1.34.4 |
| Fedoraproject | Fedora | 33 |
References
- https://lists.wikimedia.org/pipermail/mediawiki-l/2020-September/048480.htmlMailing List, Vendor Advisory
- https://lists.wikimedia.org/pipermail/mediawiki-l/2020-September/048488.htmlMailing List, Vendor Advisory
- https://phabricator.wikimedia.org/T251661Exploit, Vendor Advisory
- https://lists.wikimedia.org/pipermail/mediawiki-l/2020-September/048480.htmlMailing List, Vendor Advisory
- https://lists.wikimedia.org/pipermail/mediawiki-l/2020-September/048488.htmlMailing List, Vendor Advisory
- https://phabricator.wikimedia.org/T251661Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-25827?
How severe is CVE-2020-25827?
How do I fix CVE-2020-25827?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-2582Vulnerability in the Oracle iStore product of Oracle E-Busin…8.2
- CVE-2020-25820BigBlueButton before 2.2.7 allows remote authenticated users…6.5
- CVE-2020-25821peg-markdown 0.4.14 has a NULL pointer dereference in proces…7.5
- CVE-2020-25824Telegram Desktop through 2.4.3 does not require passcode ent…2.4
- CVE-2020-25825In Octopus Deploy 3.1.0 to 2020.4.0, certain scripts can rev…7.5
- CVE-2020-25826PingID Integration for Windows Login before 2.4.2 allows loc…7.8
- CVE-2020-25828An issue was discovered in MediaWiki before 1.31.10 and 1.32…6.1
- CVE-2020-25829An issue has been found in PowerDNS Recursor before 4.1.18, …7.5
- CVE-2020-2583Vulnerability in the Java SE, Java SE Embedded product of Or…3.7
- CVE-2020-25830An issue was discovered in MantisBT before 2.24.3. Improper …4.8
- CVE-2020-25832Reflected Cross Site scripting vulnerability on Micro Focus …5.4
- CVE-2020-25833Persistent cross-Site Scripting vulnerability on Micro Focus…4.8
Are you affected by CVE-2020-25827?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
