CVE-2012-1581Mediawiki vulnerability

CWE-2647 documents5 sources
Severity
5.0MEDIUMNVD
EPSS
0.5%
top 32.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 9
Latest updateMay 17

Description

MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 uses weak random numbers for password reset tokens, which makes it easier for remote attackers to change the passwords of arbitrary users.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/mediawiki< mediawiki 1:1.15.5-9 (bookworm)
Debianmediawiki/mediawiki< 1:1.15.5-9+3
NVDmediawiki/mediawiki7 versions+6

🔴Vulnerability Details

2
GHSA
GHSA-fpjv-7xrc-6c45: MediaWiki 12022-05-17
OSV
CVE-2012-1581: MediaWiki 12012-09-09

📋Vendor Advisories

1
Debian
CVE-2012-1581: mediawiki - MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 uses weak random numbers...2012

💬Community

3
Bugzilla
CVE-2012-1581 mediawiki (v1.18.2): Insecure generation of password reset tokens2012-03-23
Bugzilla
CVE-2012-1581 mediawiki (v1.18.2): Insecure generation of password reset tokens [epel-5]2012-03-23
Bugzilla
CVE-2012-1578 CVE-2012-1580 CVE-2012-1581 mediawiki various flaws [fedora-all]2012-03-23
CVE-2012-1581 — Debian Mediawiki vulnerability | cvebase