An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. CheckUser TokenManager insecurely uses AES-CTR encryption with a repeated (aka re-used) nonce, allowing an adversary to decrypt.
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mediawiki | Mediawiki | * | 1.35.9 (excluding) |
Mediawiki | Mediawiki | 1.36.0 (including) | 1.38.5 (excluding) |
Mediawiki | Mediawiki | 1.39.0 (including) | 1.39.0 (including) |
Mediawiki | Mediawiki | 1.39.0-rc0 (including) | 1.39.0-rc0 (including) |
Mediawiki | Mediawiki | 1.39.0-rc1 (including) | 1.39.0-rc1 (including) |