CVE-2015-8009

critical
Published 2017-07-25 · Modified 2026-05-13
CVSS v3
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
VIR risk
9.8

Description

The MWOAuthDataStore::lookup_token function in Extension:OAuth for MediaWiki 1.25.x before 1.25.3, 1.24.x before 1.24.4, and before 1.23.11 does not properly validate the signature when checking the authorization signature, which allows remote registered Consumers to use another Consumer's credentials by leveraging knowledge of the credentials.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Application impact

VendorProductVersionsFixed
mediawikimediawiki{"endIncluding":"1.23.10"}
mediawikimediawiki1.24.0
mediawikimediawiki1.24.1
mediawikimediawiki1.24.2
mediawikimediawiki1.24.3
mediawikimediawiki1.25.0
mediawikimediawiki1.25.1
mediawikimediawiki1.25.2

References

CWEs

CWE-255

💬 Discuss CVE-2015-8009 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.