High severity7.5NVD Advisory· Published Sep 27, 2020· Updated Jun 17, 2026
CVE-2020-25827
CVE-2020-25827
Description
An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limiting of OATH tokens is only done on a single site level. Thus, multiple requests can be made across many wikis/sites concurrently.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mediawiki/corePackagist | >= 1.31.0, < 1.31.9 | 1.31.9 |
mediawiki/corePackagist | >= 1.32.0, < 1.34.3 | 1.34.3 |
Affected products
4- ghsa-coords2 versions
>= 1.31.0, < 1.31.9+ 1 more
- (no CPE)range: >= 1.31.0, < 1.31.9
- (no CPE)range: < 1.31.10
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
9- phabricator.wikimedia.org/T251661nvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-rqvj-fc2x-99q6ghsaADVISORY
- lists.wikimedia.org/pipermail/mediawiki-l/2020-September/048480.htmlnvdMailing ListVendor AdvisoryWEB
- lists.wikimedia.org/pipermail/mediawiki-l/2020-September/048488.htmlnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-25827ghsaADVISORY
- github.com/FriendsOfPHP/security-advisories/blob/master/mediawiki/core/CVE-2020-25827.yamlghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RTTPZ7XMDS66I442OLLHXBDNP2LCBJU6ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/RTTPZ7XMDS66I442OLLHXBDNP2LCBJU6ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RTTPZ7XMDS66I442OLLHXBDNP2LCBJU6/nvd
News mentions
0No linked articles in our index yet.