CVE Vulnerabilities

CVE-2013-4304

Improper Authentication

Published: Jan 26, 2014 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The CentralAuth extension for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 caches a valid CentralAuthUser object in the centralauth_User cookie even when a user has not successfully logged in, which allows remote attackers to bypass authentication without a password.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Centralauth_extensionBrion_vibber- (including)- (including)
MediawikiMediawiki1.19 (including)1.19 (including)
MediawikiMediawiki1.19-beta_1 (including)1.19-beta_1 (including)
MediawikiMediawiki1.19-beta_2 (including)1.19-beta_2 (including)
MediawikiMediawiki1.19.0 (including)1.19.0 (including)
MediawikiMediawiki1.19.1 (including)1.19.1 (including)
MediawikiMediawiki1.19.2 (including)1.19.2 (including)
MediawikiMediawiki1.19.3 (including)1.19.3 (including)
MediawikiMediawiki1.19.4 (including)1.19.4 (including)
MediawikiMediawiki1.19.5 (including)1.19.5 (including)
MediawikiMediawiki1.19.6 (including)1.19.6 (including)
MediawikiMediawiki1.19.7 (including)1.19.7 (including)
MediawikiMediawiki1.20 (including)1.20 (including)
MediawikiMediawiki1.20.1 (including)1.20.1 (including)
MediawikiMediawiki1.20.2 (including)1.20.2 (including)
MediawikiMediawiki1.20.3 (including)1.20.3 (including)
MediawikiMediawiki1.20.4 (including)1.20.4 (including)
MediawikiMediawiki1.20.5 (including)1.20.5 (including)
MediawikiMediawiki1.20.6 (including)1.20.6 (including)
MediawikiMediawiki1.21 (including)1.21 (including)
MediawikiMediawiki1.21.1 (including)1.21.1 (including)

Potential Mitigations

References