Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-6597

Опубликовано: 02 фев. 2026
Источник: redhat
CVSS3: 0
EPSS Низкий

Описание

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/auth/AuthManager.Php. This issue affects MediaWiki: from * before 1.39.13, 1.42.7, 1.43.2, 1.44.0.

A flaw was found in MediaWiki, specifically within the includes/auth/AuthManager.Php program file. This vulnerability affects the authentication management component. The exact nature and impact of this flaw are not fully detailed in the available information, but it indicates a weakness in how MediaWiki handles user authentication.

Отчет

The vulnerability in MediaWiki stems from its failure to consider user autocreation as a login event for security reauthentication purposes. This could impact MediaWiki instances running on Fedora 42 and Fedora 43 if user autocreation is enabled, potentially leading to unintended security bypasses during reauthentication flows.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-654
https://bugzilla.redhat.com/show_bug.cgi?id=2436116MediaWiki: MediaWiki: Vulnerability in authentication management

EPSS

Процентиль: 6%
0.00021
Низкий

0 Low

CVSS3

Связанные уязвимости

ubuntu
около 2 месяцев назад

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/auth/AuthManager.Php. This issue affects MediaWiki: from * before 1.39.13, 1.42.7, 1.43.2, 1.44.0.

nvd
около 2 месяцев назад

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/auth/AuthManager.Php. This issue affects MediaWiki: from * before 1.39.13, 1.42.7, 1.43.2, 1.44.0.

debian
около 2 месяцев назад

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is ...

github
около 2 месяцев назад

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/auth/AuthManager.Php. This issue affects MediaWiki: from * before 1.39.13, 1.42.7, 1.43.2, 1.44.0.

CVSS3: 8.8
fstec
9 месяцев назад

Уязвимость компонента AuthManager программного средства для реализации гипертекстовой среды MediaWiki, позволяющая нарушителю получить несанкционированный доступ к компрометируемой системе

EPSS

Процентиль: 6%
0.00021
Низкий

0 Low

CVSS3