Title: MediaWiki External Authentication Plugin False Strict Function Handling Old Password Authentication Weakness
Info
Disclosure
Aug 31, 2012
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Aug 31, 2012
Description
MediaWiki contains a flaw related to external authentication plugins. The issue is triggered when the plugin returns false in its strict function. This may allow an attacker to use an old password for an account indefinitely.
Classification
Location:
Remote / Network Access
Attack Type:
Authentication Management
Impact:
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
OSVDB:
Web Related
Solution
Upgrade to version 1.18.5 or 1.19.2 or higher, as they have been reported to fix this vulnerability.