An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.9 and 1.32.x through 1.34.x before 1.34.3. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limiting of OATH tokens is only done on a single site level. Thus, multiple requests can be made across many wikis/sites concurrently.
{ "nvd_published_at": "2020-09-27T21:15:00Z", "cwe_ids": [ "CWE-307" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-05-17T21:56:33Z" }