← Back

CVE-2014-2243

nvd nist
Published: Mar 2, 2014Modified: Apr 29, 2026

JSON object

Loading...
5.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:N
Exploitability: 8.6 / Impact: 4.9
Source: NVD

Description

includes/User.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 terminates validation of a user token upon encountering the first incorrect character, which makes it easier for remote attackers to obtain access via a brute-force attack that relies on timing differences in responses to incorrect token guesses.

Affected (90)

Products: Mediawiki: Mediawiki
1 product
Mediawiki
Configuration A
90 vulnerable
Vulnerable SoftwareAffected Versions
Mediawiki
Up to 1.19.11
Version 1.1.0
Version 1.10.0
Version 1.10.0 rc1
Version 1.10.0 rc2
Version 1.10.1
Version 1.10.2
Version 1.10.3
Version 1.10.4
Version 1.11.0
Version 1.11.0 rc1
Version 1.11.1
Version 1.11.2
Version 1.11
Version 1.12.0
Version 1.12.0 rc1
Version 1.12.1
Version 1.12.2
Version 1.12.3
Version 1.12.4
Version 1.13.0
Version 1.13.0 rc1
Version 1.13.0 rc2
Version 1.13.1
Version 1.13.2
Version 1.13.3
Version 1.13.4
Version 1.14.0
Version 1.14.0 rc1
Version 1.14.1
Version 1.15.0
Version 1.15.0 rc1
Version 1.15.1
Version 1.15.2
Version 1.15.3
Version 1.15.4
Version 1.15.5
Version 1.16.0
Version 1.16.0 beta1
Version 1.16.0 beta2
Version 1.16.0 beta3
Version 1.16.1
Version 1.16.2
Version 1.17.0
Version 1.17.0 rc1
Version 1.17.1
Version 1.17.2
Version 1.17.3
Version 1.17.4
Version 1.17
Version 1.17 beta_1
Version 1.18.0
Version 1.18.0 rc1
Version 1.18.1
Version 1.18.2
Version 1.18.3
Version 1.18
Version 1.18 beta_1
Version 1.19.0
Version 1.19.10
Version 1.19.1
Version 1.19.2
Version 1.19.3
Version 1.19.4
Version 1.19.5
Version 1.19.6
Version 1.19.7
Version 1.19.8
Version 1.19.9
Version 1.19
Version 1.19 beta_1
Version 1.19 beta_2
Version 1.20.1
Version 1.20.2
Version 1.20.3
Version 1.20.4
Version 1.20.5
Version 1.20.6
Version 1.20.7
Version 1.20.8
Version 1.20
Version 1.21.1
Version 1.21.2
Version 1.21.3
Version 1.21.4
Version 1.21.5
Version 1.21
Version 1.22.0
Version 1.22.1
Version 1.22.2

Timeline

No history available yet.