Back to search
CVE-2012-4381
Published: Feb 8, 2020
Modified: Aug 6, 2024
PUBLISHED
Description
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when an authentication plugin returns a false in the strict function, could allow remote attackers to use old passwords for non-existing accounts in an external authentication system via unspecified vectors.
| Vendor | Product | Versions |
|---|---|---|
n/a | MediaWiki | affected before 1.18.5affected 1.19.x before 1.19.2 |
References
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=686330
x_refsource_MISC
http://www.openwall.com/lists/oss-security/2012/08/31/6
x_refsource_MISC
http://www.openwall.com/lists/oss-security/2012/08/31/10
x_refsource_MISC
https://bugzilla.redhat.com/show_bug.cgi?id=853442
x_refsource_MISC
https://phabricator.wikimedia.org/T41184
x_refsource_MISC
http://osvdb.org/show/osvdb/85106
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now