Loading...
Loading...
includes/User.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 terminates validation of a user token upon encountering the first incorrect character, which makes it easier for remote attackers to obtain access via a brute-force attack that relies on timing differences in responses to incorrect token guesses.
March 2, 2014
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2014-2243
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.