OSVDB ID: 85108

Title: MediaWiki External Authentication Plugin False Strict Function Handling Old Password Authentication Weakness

Info

Disclosure

Aug 31, 2012

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Aug 31, 2012

Description

MediaWiki contains a flaw related to external authentication plugins. The issue is triggered when the plugin returns false in its strict function. This may allow an attacker to use an old password for an account indefinitely.

Classification

Location: Remote / Network Access
Attack Type: Authentication Management
Impact: Loss of Integrity
Solution: Upgrade
Exploit: Exploit Unknown
Disclosure: Vendor Verified
OSVDB: Web Related

Solution

Upgrade to version 1.18.5 or 1.19.2 or higher, as they have been reported to fix this vulnerability.

Products

MediaWiki

MediaWiki

1.18.4
1.19.1

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/85108