Brion Vibber CentralAuth extension for MediaWiki

CPE Details

Brion Vibber CentralAuth extension for MediaWiki
-
2014-01-27
17h03 +00:00
2014-06-30
15h53 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:brion_vibber:centralauth_extension:-:-:-:*:-:mediawiki:*:*

Informations

Vendor

brion_vibber

Product

centralauth_extension

Version

-

Update

-

edition

-

Software Edition

-

Target Software

mediawiki

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2013-4304 2014-01-26 19h00 +00:00 The CentralAuth extension for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 caches a valid CentralAuthUser object in the centralauth_User cookie even when a user has not successfully logged in, which allows remote attackers to bypass authentication without a password.
7.5