CVE-2021-31556Improper Validation of Specified Quantity in Input in Mediawiki

Severity
9.8CRITICALNVD
EPSS
0.7%
top 28.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12
Latest updateMay 24

Description

An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. MWOAuthConsumerSubmitControl.php does not ensure that the length of an RSA key will fit in a MySQL blob.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

Also affects: Fedora 33, 34, 35

Patches

🔴Vulnerability Details

1
GHSA
GHSA-qm9m-9cq9-7p3v: An issue was discovered in the Oauth extension for MediaWiki through 12022-05-24

📋Vendor Advisories

1
Red Hat
mediawiki: OAuth extension doesn't validate length of RSA key2021-08-13
CVE-2021-31556 — Mediawiki vulnerability | cvebase