← Zuruck zu CVEs
CVE-2020-35623
HIGH7.5
Beschreibung
An issue was discovered in the CasAuth extension for MediaWiki through 1.35.1. Due to improper username validation, it allowed user impersonation with trivial manipulations of certain characters within a given username. An ordinary user may be able to login as a "bureaucrat user" who has a similar username, as demonstrated by usernames that differ only in (1) bidirectional override symbols or (2) blank space.
CVE Details
CVSS v3.1 Bewertung7.5
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht12/21/2020
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
mediawiki:mediawiki
Schwachen (CWE)
CWE-20CWE-706
Referenzen
https://github.com/CWRUChielLab/CASAuth/pull/11(cve@mitre.org)
https://phabricator.wikimedia.org/T263498(cve@mitre.org)
https://github.com/CWRUChielLab/CASAuth/pull/11(af854a3a-2127-422b-91ae-364da2661108)
https://phabricator.wikimedia.org/T263498(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.