CVE-2025-6597

Description

A flaw was found in MediaWiki, specifically within the includes/auth/AuthManager.Php program file. This vulnerability affects the authentication management component. The exact nature and impact of this flaw are not fully detailed in the available information, but it indicates a weakness in how MediaWiki handles user authentication.

Statement

The vulnerability in MediaWiki stems from its failure to consider user autocreation as a login event for security reauthentication purposes. This could impact MediaWiki instances running on Fedora 42 and Fedora 43 if user autocreation is enabled, potentially leading to unintended security bypasses during reauthentication flows.

Mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Understanding the Weakness (CWE)

Access Control

Technical Impact: Gain Privileges or Assume Identity

If the single factor is compromised (e.g. by theft or spoofing), then the integrity of the entire security mechanism can be violated with respect to the user that is identified by that factor.

Non-Repudiation

Technical Impact: Hide Activities

It can become difficult or impossible for the product to be able to distinguish between legitimate activities by the entity who provided the factor, versus illegitimate activities by an attacker.

Frequently Asked Questions

Want to get errata notifications? Sign up here.