CWRUChielLab/CASAuth

CWRUChielLab/CASAuth

Releases4
Frequency1 year 5 months
Last Release
Stars11
A modified version of the CASAuth plugin found here: http://www.mediawiki.org/wiki/Extension:CASAuthentication

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH5 MEDIUM

An issue was discovered in the CasAuth extension for MediaWiki through 1.35.1. Due to improper username validation, it allowed user impersonation with trivial manipulations of certain characters within a given username. An ordinary user may be able to login as a "bureaucrat user" who has a similar username, as demonstrated by usernames that differ only in (1) bidirectional override symbols or (2) blank space.