CVE Vulnerabilities

CVE-2015-8626

Published: Mar 23, 2017 | Modified: Mar 27, 2017
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The User::randomPassword function in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 generates passwords smaller than $wgMinimalPasswordLength, which makes it easier for remote attackers to obtain access via a brute-force attack.

Affected Software

Name Vendor Start Version End Version
Mediawiki Mediawiki * 1.23.11 (including)
Mediawiki Mediawiki 1.24.0 (including) 1.24.0 (including)
Mediawiki Mediawiki 1.24.1 (including) 1.24.1 (including)
Mediawiki Mediawiki 1.24.2 (including) 1.24.2 (including)
Mediawiki Mediawiki 1.24.3 (including) 1.24.3 (including)
Mediawiki Mediawiki 1.24.4 (including) 1.24.4 (including)
Mediawiki Mediawiki 1.25.0 (including) 1.25.0 (including)
Mediawiki Mediawiki 1.25.1 (including) 1.25.1 (including)
Mediawiki Mediawiki 1.25.2 (including) 1.25.2 (including)
Mediawiki Mediawiki 1.25.3 (including) 1.25.3 (including)
Mediawiki Mediawiki 1.26.0 (including) 1.26.0 (including)
Mediawiki Ubuntu artful *
Mediawiki Ubuntu precise *
Mediawiki Ubuntu trusty *
Mediawiki Ubuntu upstream *
Mediawiki Ubuntu vivid *
Mediawiki Ubuntu wily *
Mediawiki Ubuntu yakkety *
Mediawiki Ubuntu zesty *

References