Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-8623

Опубликовано: 23 мар. 2017
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8
CVSS3: 8.8

Описание

The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12 and 1.24.x before 1.24.5 does not perform token comparison in constant time before returning, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8624.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

1:1.27.4-3
cosmic

not-affected

1:1.31.1-3
devel

not-affected

1:1.31.1-3
disco

not-affected

1:1.31.1-3
esm-apps/bionic

not-affected

1:1.27.4-3
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needed]
precise

ignored

end of life
precise/esm

DNE

precise was needed
trusty

ignored

end of standard support

Показывать по

EPSS

Процентиль: 33%
0.00128
Низкий

6.8 Medium

CVSS2

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
почти 9 лет назад

The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12 and 1.24.x before 1.24.5 does not perform token comparison in constant time before returning, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8624.

CVSS3: 8.8
debian
почти 9 лет назад

The User::matchEditToken function in includes/User.php in MediaWiki be ...

CVSS3: 8.8
github
больше 3 лет назад

The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12 and 1.24.x before 1.24.5 does not perform token comparison in constant time before returning, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8624.

EPSS

Процентиль: 33%
0.00128
Низкий

6.8 Medium

CVSS2

8.8 High

CVSS3