Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8h72-c6mj-ffxx

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12 and 1.24.x before 1.24.5 does not perform token comparison in constant time before returning, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8624.

The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12 and 1.24.x before 1.24.5 does not perform token comparison in constant time before returning, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8624.

EPSS

Процентиль: 33%
0.00128
Низкий

8.8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 9 лет назад

The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12 and 1.24.x before 1.24.5 does not perform token comparison in constant time before returning, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8624.

CVSS3: 8.8
nvd
почти 9 лет назад

The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12 and 1.24.x before 1.24.5 does not perform token comparison in constant time before returning, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8624.

CVSS3: 8.8
debian
почти 9 лет назад

The User::matchEditToken function in includes/User.php in MediaWiki be ...

EPSS

Процентиль: 33%
0.00128
Низкий

8.8 High

CVSS3

Дефекты

CWE-352