CVE-2015-8624
published 2017-03-23CVE-2015-8624: The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 does…
PriorityP337high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
0.75%
51.1th percentile
The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 does not perform token comparison in constant time before determining if a debugging message should be logged, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8623.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mediawiki | < mediawiki 1:1.25.5-1 (bookworm) | mediawiki 1:1.25.5-1 (bookworm) |
| mediawiki | mediawiki | <= 1.23.11 | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | >= 0 < 1:1.25.5-1 | 1:1.25.5-1 |
| mediawiki | mediawiki | >= 0 < 1:1.25.5-1 | 1:1.25.5-1 |
| mediawiki | mediawiki | >= 0 < 1:1.25.5-1 | 1:1.25.5-1 |
| mediawiki | mediawiki | >= 0 < 1:1.25.5-1 | 1:1.25.5-1 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3h2m-jjrw-87hw: The User::matchEditToken function in includes/User
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2015-8624 [HIGH] CWE-352 GHSA-3h2m-jjrw-87hw: The User::matchEditToken function in includes/User
The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 does not perform token comparison in constant time before determining if a debugging message should be logged, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8623.
GHSA
GHSA-8h72-c6mj-ffxx: The User::matchEditToken function in includes/User
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2015-8623 [HIGH] CWE-352 GHSA-8h72-c6mj-ffxx: The User::matchEditToken function in includes/User
The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12 and 1.24.x before 1.24.5 does not perform token comparison in constant time before returning, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8624.
OSV
CVE-2015-8624: The User::matchEditToken function in includes/User
osv·2017-03-23·CVSS 8.8
CVE-2015-8624 [HIGH] CVE-2015-8624: The User::matchEditToken function in includes/User
The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 does not perform token comparison in constant time before determining if a debugging message should be logged, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8623.
OSV
CVE-2015-8623: The User::matchEditToken function in includes/User
osv·2017-03-23·CVSS 8.8
CVE-2015-8623 [HIGH] CVE-2015-8623: The User::matchEditToken function in includes/User
The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12 and 1.24.x before 1.24.5 does not perform token comparison in constant time before returning, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8624.
Debian
CVE-2015-8624: mediawiki - The User::matchEditToken function in includes/User.php in MediaWiki before 1.23....
vendor_debian·2015·CVSS 8.8
CVE-2015-8624 [HIGH] CVE-2015-8624: mediawiki - The User::matchEditToken function in includes/User.php in MediaWiki before 1.23....
The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 does not perform token comparison in constant time before determining if a debugging message should be logged, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8623.
Scope: local
bookworm: resolved (fixed in 1:1.25.5-1)
bullseye: resolved (fixed in 1:1.25.5-1)
forky: resolved (fixed in 1:1.25.5-1)
sid: resolved (fixed in 1:1.25.5-1)
trixie: resolved (fixed in 1:1.25.5-1)
Debian
CVE-2015-8623: mediawiki - The User::matchEditToken function in includes/User.php in MediaWiki before 1.23....
vendor_debian·2015·CVSS 8.8
CVE-2015-8623 [HIGH] CVE-2015-8623: mediawiki - The User::matchEditToken function in includes/User.php in MediaWiki before 1.23....
The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12 and 1.24.x before 1.24.5 does not perform token comparison in constant time before returning, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8624.
Scope: local
bookworm: resolved (fixed in 1:1.25.5-1)
bullseye: resolved (fixed in 1:1.25.5-1)
forky: resolved (fixed in 1:1.25.5-1)
sid: resolved (fixed in 1:1.25.5-1)
trixie: resolved (fixed in 1:1.25.5-1)
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2015/12/21/8http://www.openwall.com/lists/oss-security/2015/12/23/7https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-December/000186.htmlhttps://phabricator.wikimedia.org/T119309http://www.openwall.com/lists/oss-security/2015/12/21/8http://www.openwall.com/lists/oss-security/2015/12/23/7https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-December/000186.htmlhttps://phabricator.wikimedia.org/T119309
2017-03-23
Published