The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user.
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mediawiki | Mediawiki | * | 1.19.9 (excluding) |
Mediawiki | Mediawiki | 1.20 (including) | 1.20.8 (excluding) |
Mediawiki | Mediawiki | 1.21 (including) | 1.21.3 (excluding) |
Mediawiki | Ubuntu | lucid | * |
Mediawiki | Ubuntu | precise | * |
Mediawiki | Ubuntu | quantal | * |
Mediawiki | Ubuntu | saucy | * |
Mediawiki | Ubuntu | upstream | * |
Such a scenario is commonly observed when: