CVE-2013-4304

Brion Vibber Centralauth Extension - Authentication Bypass

Title source: rule

Description

The CentralAuth extension for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 caches a valid CentralAuthUser object in the centralauth_User cookie even when a user has not successfully logged in, which allows remote attackers to bypass authentication without a password.

Scores

EPSS 0.0033
EPSS Percentile 55.7%

Classification

CWE
CWE-287
Status draft

Affected Products (21)

brion_vibber/centralauth_extension
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
mediawiki/mediawiki
... and 6 more

Timeline

Published Jan 26, 2014
Tracked Since Feb 18, 2026