Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The CentralAuth extension for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 caches a valid CentralAuthUser object in the centralauth_User cookie even when a user has not successfully logged in, which allows remote attackers to bypass authentication without a password.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MediaWiki CentralAuth扩展身份认证绕过漏洞
Vulnerability Description
MediaWiki是美国维基媒体(Wikimedia)基金会和MediaWiki志愿者共同开发维护的一套自由免费的基于网络的Wiki引擎。CentralAuth是其中的一个可在项目之间实现全球账户共享的扩展。 MediaWiki的CentralAuth扩展中存在安全漏洞,该漏洞源于程序没有删除‘centralauth_User ’cookie中的有效的CentralAuthUser对象。远程攻击者可利用该漏洞绕过身份验证机制。以下版本受到影响:MediaWiki 1.19.8之前的1.19.x版本,1.2
CVSS Information
N/A
Vulnerability Type
N/A